You are viewing a single comment's thread from:

RE: New NPM Supply Chain Attack, so I released a new scanner.

in #security14 days ago

I am guesstimating that most of us (on Hive) don't use these things (aka newest 1-year-old packages)... but I am seeing more and more that most of the new AI problems will come with newly released packages... where Enterprise people are trying to sell the idea that everyone needs to update ASAP because of being protected.... and then they get hijacked with this stupidity.

And this one was just a simple idiot test, with at most 1 year of preparation, due to how easy it might have been to hide it back a year ago, with the first version.

More will come... especially to uncurated repos.