DangerousDetlef@lemmy.worldtoTechnology@lemmy.world•Attackers invite targets to collaborate on a project, convincing them to download and run a repository with malicious npm dependencies.English
12·
1 year agoThe really scary thing is probably the malicious npm dependencies. If I think about the projects at work with and all the different packages and the hundreds of dependencies no one knows. And it’s probably even worse in really big companies like Microsoft or Facebook, they probably got thousands across their products. I hope for us all that they scan them very regularly.
Yeah, I actually had a nice Monday for once. After seeing this, it suddenly got worse again. Much worse. Thank you for that.