programming.dev
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
KelsonV@lemmy.world to Technology@lemmy.worldEnglish · 2 years ago

Attackers invite targets to collaborate on a project, convincing them to download and run a repository with malicious npm dependencies.

github.blog

external-link
message-square
13
link
fedilink
143
external-link

Attackers invite targets to collaborate on a project, convincing them to download and run a repository with malicious npm dependencies.

github.blog

KelsonV@lemmy.world to Technology@lemmy.worldEnglish · 2 years ago
message-square
13
link
fedilink
Security alert: social engineering campaign targets technology industry employees - The GitHub Blog
github.blog
external-link
GitHub has identified a low-volume social engineering campaign that targets the personal accounts of employees of technology firms. No GitHub or npm systems were compromised in this campaign. We’re publishing this blog post as a warning for our customers to prevent exploitation by this threat actor.
  • style99@kbin.social
    link
    fedilink
    arrow-up
    1
    ·
    2 years ago

    Linux distros typically use a key signing party to help shore up their security concerns, but I wonder how github would go about implementing something like that.

Technology@lemmy.world

technology@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


  • @[email protected]
  • @[email protected]
  • @[email protected]
  • @[email protected]
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 4.78K users / day
  • 9.31K users / week
  • 17.6K users / month
  • 37K users / 6 months
  • 1.04K local subscribers
  • 70K subscribers
  • 14.9K Posts
  • 603K Comments
  • Modlog
  • mods:
  • L3s@lemmy.world
  • enu@lemmy.world
  • Technopagan@lemmy.world
  • L4sBot@lemmy.world
  • L3s@hackingne.ws
  • L4s@hackingne.ws
  • BE: 0.19.11
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org