Malicious Postinstall Hook Found in 700 GitHub Repos, Including Node Projects (socket.dev) 18 points by 882542F3884314B 3mo ago ↗ HN
[–] gnabgib 3mo ago ↗ All Composer packages (but the malicious part is in the node dependency)Effected*> Use effect as a noun to refer to a change resulting from something.
[–] tedchs 3mo ago ↗ How many more examples of malware postinstall scripts do we need before Node quits running them by default, without warning?
[–] nullsex 3mo ago ↗ Title is somewhat misleading. "Node projects" mean projects using nodejs as opposed to projects under the Node.js org.
[–] kspetkov79 3mo ago ↗ Postinstall hooks are a footgun. The bad part here is that people reviewing a PHP package may not even look closely at package.json.
5 comments
[ 3.9 ms ] story [ 28.0 ms ] threadEffected*
> Use effect as a noun to refer to a change resulting from something.