Malicious Postinstall Hook Found in 700 GitHub Repos, Including Node Projects(socket.dev)
17 分 | 作者 882542F3884314B 15小时前
5 条评论
- kspetkov79 12小时前Postinstall hooks are a footgun. The bad part here is that people reviewing a PHP package may not even look closely at package.json.
- tedchs 14小时前How many more examples of malware postinstall scripts do we need before Node quits running them by default, without warning?
- nullsex 13小时前[dead]
- gnabgib 15小时前All Composer packages (but the malicious part is in the node dependency)
Effected*
> Use effect as a noun to refer to a change resulting from something.
- nullsex 13小时前Title is somewhat misleading. "Node projects" mean projects using nodejs as opposed to projects under the Node.js org.
- ryanshrott 1小时前[flagged]