Mac to [email protected] • 1 year agoSSH keys stolen by stream of malicious PyPI and npm packageswww.bleepingcomputer.comexternal-linkmessage-square10fedilinkarrow-up1122arrow-down12cross-posted to: [email protected][email protected]
arrow-up1120arrow-down1external-linkSSH keys stolen by stream of malicious PyPI and npm packageswww.bleepingcomputer.comMac to [email protected] • 1 year agomessage-square10fedilinkcross-posted to: [email protected][email protected]
minus-square@platypus_plumbalink1•1 year agoIt’s honestly crazy that tools like npm don’t force you to encrypt the tokens for the npm repos. They don’t even support it. Any stupid read_file() with http.post() can screw 1000 people.
It’s honestly crazy that tools like npm don’t force you to encrypt the tokens for the npm repos. They don’t even support it. Any stupid read_file() with http.post() can screw 1000 people.