Yet another NPM supply chain attack

Dex-chan lover
Joined
Jul 27, 2024
Messages
1,130
https://x.com/intcyberdigest/status/2062525624695083435

Or if you don't want to open twitter:
"‼️🚨 A new npm supply-chain attack compromised 57 packages across over 286 malicious versions in under 2 hours. The attackers used self-replicating malware, a new version of the Miasma worm, which also used evasion techniques to stay under the radar.

The payload targets CI/CD and developer credentials, including GitHub Actions secrets, cloud credentials, Vault tokens, SSH keys, npm and GitHub tokens, and password-manager stores. This variant also injects AI coding assistant config files at .claude, .cursor, .gemini, and .vscode paths, a separate persistence and repo-poisoning angle."

the fact that they have not yet enforced proper MFA for major pakcage maintainers convinces me theyre doign this shilt on puerpose
"no way to prevent this" says only package manager where this is a regular occurrence
rgar9l.png
 
Group Leader
Joined
Nov 9, 2024
Messages
103
The best thing one could ever do for security is trust arbitrary user input and remote resources with no verification done whatsoever. Just grab your favorite package manager and tell it "I want this thing, and I don't give a F what it ends up being." Best, ever. It's so easy and nice.
 
NTRbro
Group Leader
Joined
Jun 12, 2020
Messages
18,411
I'm kind of afraid of making fun of @pedronimo now after reading this.

I think she could legit hack my account if she really felt like it.
 
Dex-chan lover
Joined
Apr 22, 2023
Messages
108
Javascript became suck mess in 2026.
It's been a mess since people decided to start running it on the server side, and pulling in hundreds (sometimes thousands) of third-party packages while auditing precisely none of the code. Maybe all these recent attacks will make people realise how insane that is.

Makes me glad I left the shitshow that is modern web dev years ago, we don't have to deal with this shit on the embedded side lol
 
Dex-chan lover
Joined
Jul 27, 2024
Messages
1,130
It's been a mess since people decided to start running it on the server side, and pulling in hundreds (sometimes thousands) of third-party packages while auditing precisely none of the code. Maybe all these recent attacks will make people realise how insane that is.

Makes me glad I left the shitshow that is modern web dev years ago, we don't have to deal with this shit on the embedded side lol
The web moves scarily quick for me. I'm scared of putting my heart and soul into a web project only for it to have a shelf life of ~2 years at most.

Embedded is nice though. It feels so good to physcially touch something you've made in your hands, right? It's like i've got little PCB babies.
 
Dex-chan lover
Joined
Apr 22, 2023
Messages
108
The web moves scarily quick for me. I'm scared of putting my heart and soul into a web project only for it to have a shelf life of ~2 years at most.
Right there with you, I check in every 6 months or so and the landscape's totally different every time, it's crazy.

Embedded is nice though. It feels so good to physcially touch something you've made in your hands, right? It's like i've got little PCB babies.
Yeah, iterating from breadboard->perfboard prototype->PCB is really nice too, gives a real sense of actual progression through a project. It does hurt that much more when some dumbass misreads a schematic and ends up frying several of the boards though...

*It was me. I am the dumbass.
 
Dex-chan lover
Joined
Jul 27, 2024
Messages
1,130
Yeah, iterating from breadboard->perfboard prototype->PCB is really nice too, gives a real sense of actual progression through a project. It does hurt that much more when some dumbass misreads a schematic and ends up frying several of the boards though...

*It was me. I am the dumbass.
There's a reason why they say 'Hardware is hard' lol

I can't really feel the same sense of completion when i'm writing software. I think it's because when i turn the computer off it's all gone. unless i've got tmux on my phone lmao
 
Last edited:

Users who are viewing this thread

Top