-
Notifications
You must be signed in to change notification settings - Fork 1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
npm "rc" #10
Comments
I picked this up from https://twitter.com/ReversingLabs/status/1456363796751175687 |
Big day for npm compromises. I imagine pressure is mounting on them to mandate 2fa at the minimum for devs of major packages. rc has over 14 million downloads a week! |
There's a little bit more reporting at https://therecord.media/malware-found-in-coa-and-rc-two-npm-packages-with-23m-weekly-downloads/
|
Added to cncf/tag-security#812 |
Similar to the "coa" attack at #9 this involves injecting malware into the system.
dominictarr/rc#131
advisory at GHSA-g2q5-5433-rhrf notes that the analysis is still in progress, and reads in part:
The text was updated successfully, but these errors were encountered: