[a / b / c / d / e / f / g / gif / h / hr / k / m / o / p / r / s / t / u / v / vg / vm / vmg / vr / vrpg / vst / w / wg] [i / ic] [r9k / s4s / vip] [cm / hm / lgbt / y] [3 / aco / adv / an / bant / biz / cgl / ck / co / diy / fa / fit / gd / hc / his / int / jp / lit / mlp / mu / n / news / out / po / pol / pw / qst / sci / soc / sp / tg / toy / trv / tv / vp / vt / wsg / wsr / x / xs] [Settings] [Search] [Mobile] [Home]
Board
Settings Mobile Home
/g/ - Technology


Thread archived.
You cannot reply anymore.


[Advertise on 4chan]


File: 1773184734697487.jpg (33 KB, 564x306)
33 KB
33 KB JPG
https://xcancel.com/feross/status/2038807290422370479
>CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages.
>The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise.
>This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now.
>Deobfuscates embedded payloads and operational strings at runtime
>Dynamically loads fs, os, and execSync to evade static analysis
>Executes decoded shell commands
>Stages and copies payload files into OS temp and Windows ProgramData directories
>Deletes and renames artifacts post-execution to destroy forensic evidence
>>
>>108490170
I don't use node. This does not effect me. I don't pull random jeep package from the Internet like a street shitter.
>>
>>108490209
Well jeet this might still AFFECT you by compromising a service you use
>>
>>108490216
I don't use any services other than 4chins.
>>
>goyimscript
Lmao
>>
is this confirmed?
>>
maybe this will teach people to stop using jeetcode and write programs from scratch like a real man
>>
why can humans audit the packages they use before updtooding?
i thought they were better than chatgpt and made no mistakes?
>>
File: cyberpunk but retarded.png (205 KB, 599x818)
205 KB
205 KB PNG
I thought we were supposed to have flying cars
>>
>>108490480
>it's another "jeets talking to each other using AI" episode
>>
>>108490170
Deserved
>>
>>108490170
everyone who installs a dependency for a thin wapper around fetch() deserves to get pwned



[Advertise on 4chan]

Delete Post: [File Only] Style:
[Disable Mobile View / Use Desktop Site]

[Enable Mobile View / Use Mobile Site]

All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.