[a / b / c / d / e / f / g / gif / h / hr / k / m / o / p / r / s / t / u / v / vg / vm / vmg / vr / vrpg / vst / w / wg] [i / ic] [r9k / s4s / vip] [cm / hm / lgbt / y] [3 / aco / adv / an / bant / biz / cgl / ck / co / diy / fa / fit / gd / hc / his / int / jp / lit / mlp / mu / n / news / out / po / pol / pw / qst / sci / soc / sp / tg / toy / trv / tv / vp / vt / wsg / wsr / x / xs] [Settings] [Search] [Mobile] [Home]
Board
Settings Mobile Home
/g/ - Technology


Thread archived.
You cannot reply anymore.


[Advertise on 4chan]


File: jjj.png (413 KB, 1079x533)
413 KB
413 KB PNG
in the span of about two hours:

>a nuclear bomb of malware hits the Internet (The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package tthat installs a RAT on your machine)
>Google officially warns that crypto is fucked if it doesn’t get post quantum immediately

The payload is a cross-platform RAT:

>macOS: binary disguised under Apple cache naming conventions

>Windows: hidden PowerShell script with execution policy bypass

>Linux: Python RAT dropped to /tmp

The dropper self-destructs post-execution – inspecting node_modules after the fact reveals nothing.
>>
>>108492754
Lucky for me. I never update. Use a firewall and am still on win 7 soooo doubt this affects me
>>
>>108493743
>can't hack or anything I have norton
Hahahahaha
>>
File: CRASH.png (39 KB, 889x556)
39 KB
39 KB PNG
>>108492754
buffet aint been shit since Charlie quit
>>
>>108492754
>linux
I have /tmp as separated partition (with /var/tmp bound) with noexec, nosuid and nodev. Suck my dick.
>>
>>108492754
>two hours
that google quantum thing was last week.
>>
>>108492754
>a RAT
Will mouse traps around the computer help
>>
File: RAT_evolution.jpg (76 KB, 1440x877)
76 KB
76 KB JPG
>>108494156
>mouse trap
when was the last time you seen a RAT?
They're big bastards now, and getting bigger. They'll bust your door in and laugh at your 'mouse traps'. Pretty soon, you'll need bear traps for the fuckers.
>>
>>108492754
That didn't happen, stop making shit up
>>
>>108492754
>using axios instead of tanstack
lol
>>
>>108492754
Post quantum chains exist already, the issue is that known quantum resistance encryption isn't yet tested to be resistant to conventional attacks, IIRC one of the quantum algorithms was already bruteforced manually
>>
>>108492754
>Linux: Python RAT dropped to /tmp
>reboot computer
fixed
>she doesn't use a POSIX-compliant distro
ngmi
>>
File: 1772368083892422.png (4 KB, 166x82)
4 KB
4 KB PNG
Claude scanned and removed all the viruses after 45 seconds, AI Chads keep winning
>>
wtf, isn't axios that news site that looks AI written but totally isn't?
>>
>>108494279
I thought it's that async http request js package used in react slop
>>
>>108494232
>tfw in the giant RATs timeline
>>
>>108494299
Yes; but much wider than React-slop alone. It has 170k+ direct dependents. And that's ONLY the direct dependents.
The axios package is literally one of the widest used packages in the entire NPM ecosystem.
>>
axios news on axios npm:
https://www.axios.com/2026/03/31/north-korean-hackers-implicated-in-major-supply-chain-attack
>>
imagine using axios when fetch exists
fucking losers
>>
axios had no use case
>>
I've never heard of Axios before, will this affect me?
>>
File: 1748736249832799.jpg (91 KB, 1600x900)
91 KB
91 KB JPG
>>108494701
this will affect every vibeslopper because the trash LLMs make you use axios instead of fetch lmao. get rekted bitches
>>
>>108494617
imagine using fetch when XMLHttpRequest exists
fucking zoomers
>>
>>108494730
So am I basically fine if I don't run AI shit on my PC and just use Firefox?
>>
>>108494743
yeah, should be
>>
Faggots who use Javascript and Python deserve this. Learn C and lower my RAM usage, kthxbai
>>
>>108492754
do any important programs use that shit or is it a Nichtsburger
>>
File: 1771535031018966.png (82 KB, 251x201)
82 KB
82 KB PNG
>>108494232
>>108494232
el RATo
>>
>>108492754
put /tmp on a log file system(lol)
>>
File: OH SHIT A RAT.gif (288 KB, 220x275)
288 KB
288 KB GIF
OH SHIT A RAT
>>
File: 1759132615911859.png (113 KB, 247x240)
113 KB
113 KB PNG
>>108493743
windows 7, famously unhackable.
kek.
>>
JS-bros... do we have them rabies...?
>>
>>108494232
thinly veiled xfce propaganda
>>
Does this affect website users or only webdevs?
>>
>>108494544
not clicking that malware link
>>
>>108492754
>axios
what's wrong with fetch?
>>
>>108494232
I've seen rats about 30 or 40cm of body length like 10 years ago around my summer house, can't imagine how big they could have gotten now if they keep getting bigger.
>>
>>108495690
>10 years ago
trust me, you don't wanna know
Humanity is asleep on this, what will soon be Public Enemy Numero Uno. The RAT got expert at hiding, breeding and growing the fuck bigger. Soon, its us who'll need to be hiding.
>>
>>108492754
If I don't have npm installed, am I safe? I'm a retard who just updated his whole Linux system (including Python) a few days ago.
>>
>>108492754
>execution policy bypass
properly configured machine prevents this
>>
>>108495684
nothing. nowadays fetch is the better way.
it's just vibe code sloppers don't know shit and use what their overlord suggests, and it is suggesting Axios most of the time.
>>
>>108492754
>read the github page
>doesnt even attempt to explain what it is
google is now filled with useless zero information news articles. is there anywere an actual attempt to list compromised software which depends on this slop?
>>
>>108496563
https://safedep.io/axios-npm-supply-chain-compromise/
>>
Using Win98 here. Security through obscurity, bitch. Noone bothers to make malware for something that's not used widely.
>>
>>108496734
The real reason is that they know that you're so poor that you have nothing worth stealing.
>>
>>108496933
nta but getting a good Windows 98 setup is quite expensive. most people's macbooks are worth less.



[Advertise on 4chan]

Delete Post: [File Only] Style:
[Disable Mobile View / Use Desktop Site]

[Enable Mobile View / Use Mobile Site]

All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.