|
|
|
|
|
by thenewwazoo
2899 days ago
|
|
* eslint gets compromised, and 3.7.2 is published * eslint user FooCorp also gets compromised, and a similarly-malicious version of foolib-js gets published that includes the _same code_ to steal tokens * npm invalidates all tokens * you decide to use foolib-js, and your newly-minted token is now compromised npm are fucking this up, and royally. |
|
> We determined that access tokens for approximately 4,500 accounts could have been obtained before we acted to close this vulnerability. However, we have not found evidence that any tokens were actually obtained or used to access any npmjs.com account during this window.[1]
I get that it's possible that other modules could already be infected, but it's also true that other modules could have been similarly infected long before this one.
[1] https://blog.npmjs.org/post/175824896885/incident-report-npm...