Hacker News new | ask | show | jobs
by lyu07282 23 days ago
They can and do indeed detect those attacks, it's just from Microsoft's POV a feature of Microsoft Defender (on Windows and Cloud) they sell:

https://www.microsoft.com/en-us/security/blog/2025/12/09/sha...

https://azure.microsoft.com/en-us/pricing/details/defender-f...

So this is presumably why they will never address this in npm itself.

1 comments

Maybe they should prove their shit works first.

What a wonderful marketing opportunity! Leave it to Microsoft to blindly ignore it.

No look at the article of this post, it's by SafeDep they are in the same business as Microsoft with their Defender product line. They both publish near identical post mortems with subtle hints at how their product would've defended you against the attack. Why should Microsoft fix the cause instead of selling the cure to each business individually?
Is the complete loss of trust in the platform they want to profit off a better alternative?
It's essential infrastructure there is only one node package manager. I'm not saying it's a good thing, I just describe the systemic reason why it's broken, because that's usually never expressed but its important.