Live data from Hacker News

NPM debug and chalk packages compromised

aikido.dev

791–796 of 796 posts

Re: NPM debug and chalk packages compromised

#792
post #9

Hi, yep I got pwned. Sorry everyone, very embarrassing. More info: - https://github.com/chalk/chalk/issues/656 - https://github.com/debug-js/debug/issues/1005#issuecomment-3... Affected packages (at least the ones I know of): - ansi-styles@6.2.2 - debug@4.4.2 (appears to have been yanked as of 8 Sep 18:09 CEST) - chalk@5.6.1 - supports-color@10.2.1 - strip-ansi@7.1.1 - ansi-regex@6.2.1 - wrap-ansi@9.0.1 - color-conve…

be careful!

Re: NPM debug and chalk packages compromised

#793
post #456

Earlier quoted context omitted.

AI based code review with escalation to a human

I'm curious :) Does the AI detect the obfuscation?

I think that would be static analysis. After processing the source code normally (looking for net & sys calls), you decode base64, concatenate all strings and process again (until decode makes no change)

Re: NPM debug and chalk packages compromised

#794
post #770

Earlier quoted context omitted.

Ironically you are being incredibly rude trying to support an argument that posting AI responses is rude. I guess we can conclude you know nothing about anything.

I never mention rudeness, I dont give a shit about random people online being "rude". It's just something I don't like, so I shared my opinion.

Still ironic. Just so you know I might have considered what you said and changed my mind, but being rude made me dismiss you immediately. Just sharing my opinion

Re: NPM debug and chalk packages compromised

#795

Earlier quoted context omitted.

Hey, new dev here. Sorry if this is a common knowledge and I am asking a stupid question. How does you getting phished affect these NPM packages? aren't these handled by NPM or the developers of them?

OP is the developer & maintainer of the affected packages, so the attacker was able to use their phished credentials to upload compromised versions to NPM.

oh! understood. thanks.

Re: NPM debug and chalk packages compromised

#796

Earlier quoted context omitted.

[flagged]

I feel like you were trying to help here, but anyone can do this for themselves. Providing information in this way sort of indicates that you don't believe that the person you're replying to can do it on their own, and for that reason it's considered rude.

I was, I was also seeing if the hackernews braintrust would freak out at AI much like reddit does, so it was sort of tongue-in-cheek experiment. And freak out they did.
Post reply on HN