Skip Navigation
The massive bug at the heart of the npm ecosystem
blog.vlt.sh The massive bug at the heart of the npm ecosystem

An article detailing the massive bug at the heart of the npm ecosystem; encompassing a lack of validation by the public registry, package manifest inconsistancies & assumptions about package managers & security products

The massive bug at the heart of the npm ecosystem
0
Hijacking S3 Buckets: New Attack Technique
checkmarx.com Hijacking S3 Buckets: New Attack Technique

Without altering a single line of code, attackers poisoned the NPM package “bignum” by hijacking the S3 bucket serving binaries necessary for its function and replacing them with malicious ones

Hijacking S3 Buckets: New Attack Technique
0
InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)MA
Markmus @lemmy.ml
Posts 3
Comments 4