schnurrito@discuss.tchncs.de to Cybersecurity@sh.itjust.worksEnglish · 2 months agoDozens of Red Hat packages backdoored through its official NPM channelarstechnica.comexternal-linkmessage-square17linkfedilinkarrow-up195arrow-down12
arrow-up193arrow-down1external-linkDozens of Red Hat packages backdoored through its official NPM channelarstechnica.comschnurrito@discuss.tchncs.de to Cybersecurity@sh.itjust.worksEnglish · 2 months agomessage-square17linkfedilink
minus-squareFizz@lemmy.nzlinkfedilinkEnglisharrow-up4arrow-down2·2 months agoI’m not familiar with npm but why is this always NPM? Is it a specific issue they have?
minus-squareBoofStroke@sh.itjust.workslinkfedilinkEnglisharrow-up25·2 months agoIt’s a “package manager” that has zero integrity checks built in. Web devs also love it. Nice combination.
minus-squarehirihit640@sh.itjust.workslinkfedilinkEnglisharrow-up2arrow-down1·2 months agobecause it’s the biggest. Just like how hackers target windows and not linux (assuming they are targeting users and not servers).
I’m not familiar with npm but why is this always NPM? Is it a specific issue they have?
It’s a “package manager” that has zero integrity checks built in. Web devs also love it. Nice combination.
Culture problem imo.
because it’s the biggest. Just like how hackers target windows and not linux (assuming they are targeting users and not servers).