What are the implications for users of FOSS? Should we not be downloading from github?
post
NPM should be destroyed, at this point… so many problems come from that place.
The same can happen for maven, crates, gomods, and other.
Yes.
The problem is [intricate dependencies]
Nah. Dependencies are fine. The method of bringing those in and validating them is where the supply-chain risk accumulates. We knew better when we still had mentors.
I just searched on GitHub for "Sha1-Hulud: The Second Coming.": 692 repositories. On the first page of results I was able to find a repo clearly made by the malware, and in that repo I was able to find someone's github token with a few applications of "decode from base64".
This is pretty bad. I don't know what exactly comes next, an awareness campaign to get people to clean their infected machines and packages?
all 8 comments