"Compromising Angular via Expired npm Publisher Email Domains" by Matthew Bryant thehackerblog.com/zero-days-wi

Man, if there's a vulnerability in the OSS supply chain, somebody's thought of it. This one seems particularly tricky to defend against, from the registry's perspective.

Follow

@nolan

Actually, this kind of attack doesn't only depend on domain names.

Any provider (or administrator) of any mailbox of a package developer might do the same.

Sign in to participate in the conversation
Qoto Mastodon

QOTO: Question Others to Teach Ourselves
An inclusive, Academic Freedom, instance
All cultures welcome.
Hate speech and harassment strictly forbidden.