This site does not allow itself to be embedded. You can still read it on the original site — the toolbar below keeps your place in the directory.
This isn't limited to NodeJS, but it seems to happen a lot more frequently in that ecosystem. A commonly used dependency gets compromised, developers install it when doing an npm install, or updating packages, and they now have a trojan running on their host. A trojan that gives the attacker access to run arbitrary code, e.g keyloggers to steal passwords as they are entered, theft of bitcoin…
Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.