NPM debug and chalk packages compromised
791–796 of 796 posts
Re: NPM debug and chalk packages compromised
#792Hi, yep I got pwned. Sorry everyone, very embarrassing. More info: - https://github.com/chalk/chalk/issues/656 - https://github.com/debug-js/debug/issues/1005#issuecomment-3... Affected packages (at least the ones I know of): - ansi-styles@6.2.2 - debug@4.4.2 (appears to have been yanked as of 8 Sep 18:09 CEST) - chalk@5.6.1 - supports-color@10.2.1 - strip-ansi@7.1.1 - ansi-regex@6.2.1 - wrap-ansi@9.0.1 - color-conve…
Re: NPM debug and chalk packages compromised
#793Earlier quoted context omitted.
AI based code review with escalation to a human
I'm curious :) Does the AI detect the obfuscation?
Re: NPM debug and chalk packages compromised
#794Earlier quoted context omitted.
Ironically you are being incredibly rude trying to support an argument that posting AI responses is rude. I guess we can conclude you know nothing about anything.
I never mention rudeness, I dont give a shit about random people online being "rude". It's just something I don't like, so I shared my opinion.
Re: NPM debug and chalk packages compromised
#795Earlier quoted context omitted.
Hey, new dev here. Sorry if this is a common knowledge and I am asking a stupid question. How does you getting phished affect these NPM packages? aren't these handled by NPM or the developers of them?
OP is the developer & maintainer of the affected packages, so the attacker was able to use their phished credentials to upload compromised versions to NPM.
Re: NPM debug and chalk packages compromised
#796Earlier quoted context omitted.
[flagged]
I feel like you were trying to help here, but anyone can do this for themselves. Providing information in this way sort of indicates that you don't believe that the person you're replying to can do it on their own, and for that reason it's considered rude.