btaf45@lemmy.world to Technology@lemmy.worldEnglish · 2 months agoHundreds of code libraries posted to NPM try to install malware on dev machinesarstechnica.comexternal-linkmessage-square35fedilinkarrow-up1251arrow-down12cross-posted to: pulse_of_truth@infosec.pubprogramming@programming.devcybersecurity@sh.itjust.works
arrow-up1249arrow-down1external-linkHundreds of code libraries posted to NPM try to install malware on dev machinesarstechnica.combtaf45@lemmy.world to Technology@lemmy.worldEnglish · 2 months agomessage-square35fedilinkcross-posted to: pulse_of_truth@infosec.pubprogramming@programming.devcybersecurity@sh.itjust.works
minus-squareKairos@lemmy.todaylinkfedilinkEnglisharrow-up7·2 months agoOr at the very fucking least require specific versions with checksums, like golang.
minus-squareLavenderDay3544@lemmy.worldlinkfedilinkEnglisharrow-up2·2 months agoI really think every package repository should be opt in and every publisher should be required to verify their identity and along with checksum verification for the downloaded files.
Or at the very fucking least require specific versions with checksums, like golang.
I really think every package repository should be opt in and every publisher should be required to verify their identity and along with checksum verification for the downloaded files.