programming.dev
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
lysdexicM to Node.jsEnglish · 2 years ago

How npm install scripts can be weaponized: A real-world example of a harmful npm package

stacklok.com

external-link
message-square
0
link
fedilink
26
external-link

How npm install scripts can be weaponized: A real-world example of a harmful npm package

stacklok.com

lysdexicM to Node.jsEnglish · 2 years ago
message-square
0
link
fedilink
How npm preinstall and postinstall scripts can serve as methods to inject malicious code into open source packages.
alert-triangle
You must log in or # to comment.

Node.js

nodejs

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 1 user / day
  • 9 users / week
  • 26 users / month
  • 39 users / 6 months
  • 98 local subscribers
  • 316 subscribers
  • 91 Posts
  • 26 Comments
  • Modlog
  • mods:
  • lysdexic
  • BE: 0.19.13
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org