▲ | maxbond 9 hours ago | |||||||||||||||||||||||||
I can understand why there's a research interest in publishing malware but I don't understand why there would be in publishing it to a language's official package repository. If you want to experiment with repositories hosting malware for some innocent reason, configure your package manager to use a self hosted repository. | ||||||||||||||||||||||||||
▲ | viraptor 8 hours ago | parent [-] | |||||||||||||||||||||||||
Because it's general and public. Then again, how would you tell the difference apart from the description? For example this https://www.npmjs.com/package/@celo/encrypted-backup is just a few lines away from a ransomware system. This https://www.npmjs.com/package/web-vuln-scanner can be both offensive and defensive. It's mostly how you use them, so there's little chance for any system to detect with certainty went no false positives. | ||||||||||||||||||||||||||
|