This site does not allow itself to be embedded. You can still read it on the original site — the toolbar below keeps your place in the directory.
This isn't limited to NodeJS, but it seems to happen a lot more frequently in
that ecosystem. A commonly used dependency gets compromised, developers install
it when doing an npm install, or updating packages, and they now have a trojan
running on their host. A trojan that gives the attacker access to run arbitrary
code, e.g keyloggers to steal passwords as they are entered, theft…
Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.