Y
Hacker News
new
|
ask
|
show
|
jobs
Malicious Postinstall Hook Found in 700 GitHub Repos, Including Node Projects
(
socket.dev
)
18 points
by
882542F3884314B
33 days ago
4 comments
kspetkov79
33 days ago
Postinstall hooks are a footgun. The bad part here is that people reviewing a PHP package may not even look closely at package.json.
link
nullsex
33 days ago
Title is somewhat misleading. "Node projects" mean projects using nodejs as opposed to projects under the Node.js org.
link
tedchs
33 days ago
How many more examples of malware postinstall scripts do we need before Node quits running them by default, without warning?
link
gnabgib
33 days ago
All Composer packages (but the malicious part is in the node dependency)
Effected*
> Use effect as a noun to refer to a change resulting from something.
link