you are viewing a single comment's thread
view the rest of the comments
[–] 24 points 2 years ago* (1 child)

Supply chain attacks are extremely cheap/easy and very effective, so get prepared for more of them in the future.

It really bothers me, that many companies make billions utilizing open source without contributing money/employees etc. to secure/supply/maintain supply chains.

  • source
  • hideshow 2 child comments
  • [–] 11 points 2 years ago (2 children)

    This one might not have been that cheap. The malicious code was added by a maintainer on the project for two years. That is some patience

  • source
  • parent
  • hideshow 4 child comments
  • [–] 6 points 2 years ago

    Agreed. I am more speaking of 'in general', for example there was a supply chain attack on a widely used npm package by writing an email to the author of the npm package. There are other 'cheap' attacks like dependency confusion, typo squatting etc.

  • source
  • parent
  • [–] 2 points 2 years ago (1 child)

    What about finding someone like this and then blackmailing them?

    That would be cheaper

  • source
  • parent
  • hideshow 2 child comments