GitLab discovers widespread NPM supply chain attack
28 points
8 hours ago
| 2 comments
| about.gitlab.com
| HN
ChrisArchitect
8 hours ago
[-]
reply
ares623
1 hour ago
[-]
Phew, thought it was another one.
reply
gchamonlive
1 hour ago
[-]
> Our internal monitoring system has uncovered multiple infected packages containing what appears to be an evolved version of the "Shai-Hulud" malware.

Although it's not entirely new, it's something else.

reply
TZubiri
1 hour ago
[-]
Not all the npm packages, but always an npm package
reply
cyanydeez
45 minutes ago
[-]
While you think this is a producer problem, it's simply a userland market.

Just like in the 90s when viruses primarily went to windows, it' wasn't some magical property of windows, it was the market of users available.

Also, following this logic, it then becomes survivorship bias, in that the more attacks they get, the more researchers spend time looking & documenting.

reply