Settings

Theme

Malicious NPM package targets prettier library

sourcecodered.com

15 points by 6mile 10 months ago · 9 comments

Reader

Hackbraten 10 months ago

So if I understand the article correctly, the malicious .exe file was disguised using a Unicode right-to-left override (RTLO) attack?

beardyw 10 months ago

> Generally, it’s a good idea not to blindly install NPM packages.

Given the nature of npm that is pretty hard to avoid.

  • 6mileOP 10 months ago

    Transitive dependencies, yeah, but top-level dependencies that you are installing with npm i or via your manifest file are areas that you do control and can manage.

null_deref 10 months ago

Very interesting read, very impressive. With GitHub’s new feature of custom repository properties it can be so easy to implement a confirmation mechanism between a repository and an npm package, but I guess it could have implemented with other means long time ago.

  • 6mileOP 10 months ago

    Thanks! Lots of tooling out there, but not much uptake. I mean, npm itself has better, more secure alternatives, but is still the most popular registry on the planet. Like, wtf?!

andrewfromx 10 months ago

wow, it ain't pretty!

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection