"Compromising Angular via Expired npm Publisher Email Domains" by Matthew Bryant thehackerblog.com/zero-days-wi

Man, if there's a vulnerability in the OSS supply chain, somebody's thought of it. This one seems particularly tricky to defend against, from the registry's perspective.

Follow

@nolan

Actually, this kind of attack doesn't only depend on domain names.

Any provider (or administrator) of any mailbox of a package developer might do the same.

Sign in to participate in the conversation
CleverLibre Social

CleverLibre Social is an inclusive social instance for open discussion, learning, and community.
All cultures welcome.
Hate speech and harassment strictly forbidden.