Thread

Zero-JS Hypermedia Browser

Relays: 5
Replies: 20
Generated: 15:08:47
FYI there is a massive cyberattack on NPM right now, package developers being attacked, nasty commits being added and published, tokens being stolen and used to corrupt more packages. The ecosystem is currently widely corrupted. We just got an advisory from the NZ government about it.
2025-09-29 03:37:37 from 1 relay(s) 13 replies ↓
Login to reply

Replies (20)

A large number of the commits over the past five years contain JavaScript which is immediately suspect.
2025-09-29 04:38:51 from 1 relay(s) ↑ Parent Reply
Like most people, I have my issues with NPM. But this is a big problem for any platform that hosts large amounts of code. You can't verify that much code for vulnerabilities. Fdroid is probably the most successful at any sort of scale.
2025-09-29 04:52:25 from 1 relay(s) ↑ Parent Reply
wallets using npm were hacked via npm malware in many occasions before i am not aware deep details - this is one loophole github verify pgp identity n sig is must also
2025-09-29 07:17:47 from 1 relay(s) ↑ Parent Reply
That's the only exciting thing in the office the whole year. They got in it quick because it feels cool to investigate things going wrong and stuff. Building new random functionality for the government must be boring as hell. It's a great procrastination device: " Boss, I can't do that high priority thing because supply chain attack"
2025-09-29 21:17:33 from 1 relay(s) ↑ Parent Reply