The OpenSourceMalware Show
This week Jenn and Paul cover: * npm Staged Publishing: npm's new feature adds a human approval checkpoint before a package goes live. Real improvement, real caveats. We walk through what it does, where it falls short, and the questions the docs still don't answer. * DPRK Axios-Linked npm Packages: Paul discovered three malicious npm packages tied to the March Axios attacker that have been quietly harvesting credentials since early April. Classic DPRK multi-use attack infrastructure, built to support Contagious Interview and TaskJacker campaigns running in parallel. * TeamPCP's Biggest Maintainer Compromise Yet: Two npm maintainers compromised. One developer maintained over 540 packages. TeamPCP published over 600 malicious versions. Three of the affected packages alone account for more than 5 million weekly downloads. * GitHub Employee Device Compromised via Poisoned VS Code Extension: A malicious Nx Console extension published May 18th made it to a GitHub employee's device, exposing an estimated 3,800 repositories. The credential theft happened seven days earlier through the TanStack compromise. We also cover the CISA "private" repository that was not private, and what both incidents say about secrets management and GitHub permissions defaults. Episode Resources: * npm Staged Publishing documentation [https://docs.npmjs.com/staged-publishing] * Axios attacker strikes again: Three npm packages hiding in plain sight for two months [https://opensourcemalware.com/blog/axios-attacker-additional-npm-packages] * TeamPCP compromises npm maintainer with over 540 packages [https://opensourcemalware.com/blog/teampcp-compromises-npm-maintainer-with-over-540-packages] * OpenSourceMalware threat report: nrwl.angular-console (Nx Console) [https://opensourcemalware.com/vscode/nrwl.angular-console] * Nx Console v18.95.0 postmortem [https://nx.dev/blog/nx-console-v18-95-0-postmortem]
5 afleveringen
Reacties
0Wees de eerste die een reactie plaatst
Meld je nu aan en word lid van de The OpenSourceMalware Show community!