Hacker Poesy
  • FAQ
  • Login
  • Public

    • Public
    • Groups
    • Recent tags
    • Popular
    • Directory

Conversation:

Notices

  1. GeniusMusing (geniusmusing)'s status on Sunday, 18-Oct-2020 20:05:49 EDT GeniusMusing GeniusMusing
    Remote profile options...
    Three npm Packages Opened Remote-Access Shells on Linux and Windows Systems Slashdothttps://nu.federati.net/url/276724 >"Three JavaScript packages have been removed from the npm portal on Thursday for containing malicious code," reports ZDNet. > >"According to advisories from the npm security team, the three JavaScript libraries opened shells on the computers of developers who …
    Sunday, 18-Oct-2020 20:05:49 EDT from nu.federati.net permalink

    Attachments

    1. geniusmusing-20201019-ostatus-3ykd.html
    • LinuxWalt (@lnxw48a1) {3EB165E0-5BB1-45D2-9E7D-93B31821F864} repeated this.
    • LinuxWalt (@lnxw48a1) {3EB165E0-5BB1-45D2-9E7D-93B31821F864} (lnxw48a1)'s status on Monday, 19-Oct-2020 00:40:45 EDT LinuxWalt (@lnxw48a1) {3EB165E0-5BB1-45D2-9E7D-93B31821F864} LinuxWalt (@lnxw48a1) {3EB165E0-5BB1-45D2-9E7D-93B31821F864}
      Remote profile options...
      • GeniusMusing
      @geniusmusing I'm sure other software repositories have this issue, but I hear about it more from Node.js / NPM.
      Monday, 19-Oct-2020 00:40:45 EDT permalink
    • GeniusMusing (geniusmusing)'s status on Monday, 19-Oct-2020 09:19:47 EDT GeniusMusing GeniusMusing
      Remote profile options...
      • LinuxWalt (@lnxw48a1) {3EB165E0-5BB1-45D2-9E7D-93B31821F864}
      @lnxw48a1 Yes, PHP and PyPI (Python) have had similar issues but it seems the more people use node/NPM than the others so it may be targeted more.

      How one man could have pwned all your PHP programs – Naked Security (2018)
      https://nakedsecurity.sophos.com/2018/08/30/how-one-man-could-have-pwned-all-your-php-programs/

      Ten Malicious Libraries Found on PyPI Python Package Index (2017)
      https://nu.federati.net/url/276735
      Monday, 19-Oct-2020 09:19:47 EDT permalink
      LinuxWalt (@lnxw48a1) {3EB165E0-5BB1-45D2-9E7D-93B31821F864} repeated this.

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • Privacy
  • Source
  • Version
  • Contact

Hacker Poesy is a GNU social hub. It runs version 1.1.3-beta3, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All Hacker Poesy content and data are available under the Creative Commons Attribution 3.0 license.

Switch to mobile site layout.