| ▲ | throwwwll 2 hours ago | ||||||||||||||||
And all of them "thought" of security as an after-after-after-after-after-thought. | |||||||||||||||||
| ▲ | freakynit 2 hours ago | parent | next [-] | ||||||||||||||||
Most of these are now building upon techniques that have already been exploited since past 1 years. This attack used 4 of those techniques. 1. Lifecycle Hook Execution 2. CI/CD Identity Plane Attacks 3. Maintainer Account Takeover and Malicious Publish 4. Self-Replicating npm Worms | |||||||||||||||||
| |||||||||||||||||
| ▲ | 2 hours ago | parent | prev [-] | ||||||||||||||||
| [deleted] | |||||||||||||||||