kyu
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
schnurrito@discuss.tchncs.de to Cybersecurity@sh.itjust.worksEnglish · 7 days ago

Dozens of Red Hat packages backdoored through its official NPM channel

arstechnica.com

external-link
message-square
19
link
fedilink
103
external-link

Dozens of Red Hat packages backdoored through its official NPM channel

arstechnica.com

schnurrito@discuss.tchncs.de to Cybersecurity@sh.itjust.worksEnglish · 7 days ago
message-square
19
link
fedilink
Anyone who has downloaded affected Red Hat packages should investigate immediately.
alert-triangle
You must log in or register to comment.
  • davidgro@lemmy.world
    link
    fedilink
    English
    arrow-up
    54
    ·
    7 days ago

    I’m beginning to think this “NPM” thing isn’t a great idea.

    • ztwhixsemhwldvka@lemmy.world
      link
      fedilink
      English
      arrow-up
      21
      ·
      7 days ago

      Its always npm

    • NotSteve_@lemmy.ca
      link
      fedilink
      English
      arrow-up
      8
      arrow-down
      2
      ·
      7 days ago

      I don’t really see how it’s NPM at fault here. This was caused by a malicious actor taking control of an account and putting out bad packages on it. It could happen on any package repository for any language

      • davidgro@lemmy.world
        link
        fedilink
        English
        arrow-up
        7
        ·
        7 days ago

        My understanding is that for most package managers the signing keys are held by a smallish number of maintainers responsible for entire sections, who presumably keep those accounts pretty tightly secured. Not impossible to take over, but it’s a smaller attack surface.

        While for NPM as far as I know every uploader keeps their own account and there’s not even signing keys to lose control of.

        • hirihit640@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          4
          ·
          6 days ago

          I’ve heard quite a few PyPi and Cargo attacks though, but I bet the main reason why hear NPM so much is simply because NPM is the biggest, and thus the most valuable target

      • MonkderVierte@lemmy.zip
        link
        fedilink
        English
        arrow-up
        4
        ·
        6 days ago

        Trust by default for a atomic packaging system. Entirely NPM’s fault.

    • Fizz@lemmy.nz
      link
      fedilink
      English
      arrow-up
      6
      arrow-down
      2
      ·
      7 days ago

      I’m not familiar with npm but why is this always NPM? Is it a specific issue they have?

      • BoofStroke@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        27
        ·
        7 days ago

        It’s a “package manager” that has zero integrity checks built in. Web devs also love it. Nice combination.

        • MonkderVierte@lemmy.zip
          link
          fedilink
          English
          arrow-up
          2
          ·
          6 days ago

          Culture problem imo.

      • hirihit640@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        6 days ago

        because it’s the biggest. Just like how hackers target windows and not linux (assuming they are targeting users and not servers).

  • homes@piefed.world
    link
    fedilink
    English
    arrow-up
    12
    arrow-down
    1
    ·
    edit-2
    7 days ago

    One day, back in 1995, I could download every red hat package onto a series of 13 floppies.

    In fact, it was required if you wanted to install red hat. So was compiling them all onto your own computer.

    How far we’ve come

  • atzanteol@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    2
    ·
    6 days ago

    Thoughts and prayers.

    https://kevinpatel.xyz/posts/no-way-to-prevent-this/

  • certified_expert@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    6 days ago

    What was the red hat meaning?

  • crandlecan@lemmy.zip
    link
    fedilink
    English
    arrow-up
    7
    arrow-down
    17
    ·
    edit-2
    7 days ago

    Just use Linux!!

    😁

    • Dr. Wesker@lemmy.sdf.org
      link
      fedilink
      English
      arrow-up
      10
      ·
      7 days ago

      Should we tell them?

      • crandlecan@lemmy.zip
        link
        fedilink
        English
        arrow-up
        3
        ·
        7 days ago

        Sssssh! They are not ready yet for The Truth 😭

    • crandlecan@lemmy.zip
      link
      fedilink
      English
      arrow-up
      6
      ·
      7 days ago

      Tough crowd, Jeez!

    • cybervegan@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      1
      ·
      6 days ago

      NPM is not a Linux thing - it’s to do with web applications, so it works on Windoze and Mac too.

      • crandlecan@lemmy.zip
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        2
        ·
        edit-2
        6 days ago

        Windoze? What’s that? Sounds like socialism 🤨 And I never eat hamburgers, just so you know

Cybersecurity@sh.itjust.works

cybersecurity@sh.itjust.works

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !cybersecurity@sh.itjust.works

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

  • Be respectful. Everyone should feel welcome here.
  • No bigotry - including racism, sexism, ableism, homophobia, transphobia, or xenophobia.
  • No Ads / Spamming.
  • No pornography.

Community Rules

  • Idk, keep it semi-professional?
  • Nothing illegal. We’re all ethical here.
  • Rules will be added/redefined as necessary.

If you ask someone to hack your “friends” socials you’re just going to get banned so don’t do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 102 users / day
  • 465 users / week
  • 1.53K users / month
  • 3.44K users / 6 months
  • 1 local subscriber
  • 10.1K subscribers
  • 4.9K Posts
  • 7.27K Comments
  • Modlog
  • mods:
  • Kid@sh.itjust.works
  • Lanky_Pomegranate530@midwest.social
  • BE: 0.19.11
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org