It's tuesday, so shai hulud is back and packages with ~2bn/mo installs have been compromised againhttps://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack
>>109458879Update is the new security
Why don't they just have AI scanning each upload for malware?
>>109458879so I assume this is a nothing burger cause the "major organizations" they mention are literal whos. no large framework affected as it appears.
UPDOOTERS BTFO ONCE AGAIN
>>109459513It probably complex, the scripts are supposed to do many things and node developers are known run cross dependencies on a one liner projects to 100k line project
In rust, this is just cargo add shai-hulud.
>>109458879That's why i would never touch something as pozzed as node.js or Python.
How many more times will this happen until they figure out a better way for distribution
node trannies, not like thisnot like this
>>109458879>Heh I'll call this shai hulud because that's dope, >hackerman and sci-fi. Just like me!
How the fuck does anyone do anything serious with npm?
>>109462411It's a collaboration problem not a distribution problem.
It's this easy:0.0.0.0 registry.npmjs.org0.0.0.0 npmjs.org0.0.0.0 npmjs.com0.0.0.0 npmjs.net0.0.0.0 npm.im0.0.0.0 yarnpkg.com
0.0.0.0 registry.npmjs.org0.0.0.0 npmjs.org0.0.0.0 npmjs.com0.0.0.0 npmjs.net0.0.0.0 npm.im0.0.0.0 yarnpkg.com