Sam (crazy candle person) ✦  pfp
Sam (crazy candle person) ✦
@samantha
Our team wrote about the ongoing attack on NPM today - 1/3 packages are now spam. ‼️ If you use NPM, your customers cred and $$$ are at risk ‼️ Here’s what the spammers are doing, and how to protect yourself from malicious packages: https://blog-npm-spam.listen-dev.pages.dev/blog/npm-registry-spam-attack/
5 replies
0 recast
0 reaction

Cameron Armstrong pfp
Cameron Armstrong
@cameron
@ian relevant to your interests
1 reply
0 recast
0 reaction

Sam (crazy candle person) ✦  pfp
Sam (crazy candle person) ✦
@samantha
Here to answer any questions if you want @ian ! Supply chain security is my bread and butter.
1 reply
0 recast
0 reaction

ianh.eth pfp
ianh.eth
@ian
Hey @samantha I've been using socket.dev and it seems to work pretty well for what we're doing. How does listen.dev compare? See screenshot, this is the level of detail we get for PRs. https://i.imgur.com/kcDDPun.jpg
1 reply
0 recast
0 reaction

Sam (crazy candle person) ✦  pfp
Sam (crazy candle person) ✦
@samantha
Thanks for sharing! We use dynamic behaviour analysis on top of static feedback which socket doesn’t. We detect behaviour at the syscalls within the kernel, so we can detect activity going in or out - some payload coming in from outside, unauthorized filesystem access during insertion, invoking child processes, etc
0 reply
0 recast
0 reaction