|
|
|
|
|
by benatkin
601 days ago
|
|
wordpress.org isn’t an intermediary, they’re the publisher, so they can’t be in the middle, and they can’t be MITM Now, the owner of a package could do a supply chain attack (with a very short chain which is why I think the concept is overhyped), and it would be a supply chain attack, but it wouldn’t be a man in the middle attack. WordPress took over ownership of it but they haven’t published malicious to it. Back when WP Engine owned it they could have published a malicious update and it would be a supply chain attack but with a very short chain unless the user installed a project that depended on it and caused it to automatically be installed. |
|
https://www.advancedcustomfields.com