Open source equals better security - /g/ (#106007909) [Archived: 111 hours ago]

Anonymous
7/24/2025, 12:22:31 PM No.106007909
Npm-logo.svg
Npm-logo.svg
md5: 0eee03dd26d28a313e7bba057f6974f3🔍
>The popular npm package "is" was infected with cross-platform malware

>The malware captures data including all environment variables (often a source of secrets such as credentials), exfiltrates them via a WebSocket connection, and provides the attacker with an interactive remote shell. The malware runs on Node.js on macOS, Linux and Windows, and persists itself if possible by overwriting an index.js file so that even deleting the node_modules directory, which stores downloaded packages, will not remove it.

https://www.theregister.com/2025/07/24/not_pretty_not_windowsonly_npm/
Replies: >>106007933 >>106007948 >>106009919 >>106009946
Anonymous
7/24/2025, 12:27:24 PM No.106007933
>>106007909 (OP)
how the fuck does this happen?

aren't there supposed to be like 10 jannies on GitHub checking every PR before merging?
Replies: >>106007953
Anonymous
7/24/2025, 12:30:03 PM No.106007948
>>106007909 (OP)
>The popular npm package "is"
Is this something "is-even"?
Replies: >>106007961
Anonymous
7/24/2025, 12:30:33 PM No.106007953
>>106007933
Apparantly maintainers fell for phishing attacks so the malware was introduced using their maintainer accounts
Anonymous
7/24/2025, 12:31:35 PM No.106007961
>>106007948
It's a 3rd party package for type checking
>javascript
Replies: >>106007992
Anonymous
7/24/2025, 12:36:15 PM No.106007992
>>106007961
I wish this shocked me
Anonymous
7/24/2025, 5:12:41 PM No.106009919
>>106007909 (OP)
> more npm malware
npm was a mistake and the people responsible for it and using it.. may god have mercy on their souls.
Anonymous
7/24/2025, 5:16:03 PM No.106009946
>>106007909 (OP)
open source equals better security if we lived in the FSF fantasy world where everyone is an expert programmer with unlimited free time and audits don't cost money
Replies: >>106010198
Anonymous
7/24/2025, 5:48:50 PM No.106010198
1746071126272367
1746071126272367
md5: 076dde33b7d6cdb9c7c59a958ba39823🔍
>>106009946
>FSF
>Open sores
Anonymous
7/24/2025, 5:52:20 PM No.106010242
>another shitty bait thread where the low IQ OP and his lower IQ followers preaching the evils of "freetardism" ignore the part where it was spotted neigh instantly and revoked with little to no damage

the reality is, in a closed ecosystem, there are even LESS people who can spot this shit at all and even less people you need to target to infect it.