Open Menu
AllLocalCommunitiesAbout
lotide
AllLocalCommunitiesAbout
Login

GitLab discovers widespread npm supply chain attack

⁨18⁩ ⁨likes⁩

Submitted ⁨⁨1⁩ ⁨week⁩ ago⁩ by ⁨cm0002@lemmy.cafe⁩ to ⁨cybersecurity@infosec.pub⁩

https://about.gitlab.com/blog/gitlab-discovers-widespread-npm-supply-chain-attack/

source

Comments

Sort:hotnewtop
  • ThatGuyNamedZeus@feddit.org ⁨1⁩ ⁨week⁩ ago

    Cool! Now consider all the others they haven’t found yet

    source
    • Skullgrid@lemmy.world ⁨1⁩ ⁨week⁩ ago

      the ones that scare me are apt and pacman and the others

      source
      • redsand@lemmy.dbzer0.com ⁨6⁩ ⁨days⁩ ago

        Those aren’t insane to audit. It’s the libraries everyone uses

        source
  • tal@lemmy.today ⁨6⁩ ⁨days⁩ ago

    The malware continuously monitors its access to GitHub (for exfiltration) and npm (for propagation). If an infected system loses access to both channels simultaneously, it triggers immediate data destruction on the compromised machine. On Windows, it attempts to delete all user files and overwrite disk sectors. On Unix systems, it uses shred to overwrite files before deletion, making recovery nearly impossible.

    shred is intended to overwrite the actual on-disk contents by overwriting data in the file prior to unlinking the files. However, shred isn’t as effective on journalled filesystems, because writing in this fashion doesn’t overwrite the contents on-disk like this. Normally, ext3, ext4, and btrfs are journalled. Most people are not running ext2, save maybe on their /boot partition.

    source
  • Lightfire228@pawb.social ⁨6⁩ ⁨days⁩ ago

    Is this different from Shai Hulud 2?

    source
  • Spellbind0127@infosec.pub ⁨6⁩ ⁨days⁩ ago

    this is an insane attack

    source