Comments

Hacker News

Because the Go and Packagist registries don't require additional publishing credentials like NPM and PyPI North Korean threat actors have been able to compromise legitimate packages via their PolinRider campaign.

by 6mile

Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • Because the Go and Packagist registries don't require additional publishing credentials like NPM and PyPI North Korean threat actors have been able to compromise legitimate packages via their PolinRider campaign.
North Korean Hackers Compromise Go and PHP Packages · Birbla