60
Axios Supply Chain Attack Pushes Cross-Platform RAT via Compromised npm Account
(thehackernews.com)
It gets better and better lol
I always advocate switching to pnpm where install scripts are disabled by default. It has plenty of security features to ward off most supply chain attacks.
Pre and post install hooks are a mistake, jfk
Welcome to the main community in programming.dev! Feel free to post anything relating to programming here!
Cross posting is strongly encouraged in the instance. If you feel your post or another person's post makes sense in another community cross post into it.
Hope you enjoy the instance!
Rules
Follow the wormhole through a path of communities !webdev@programming.dev