Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • It's time for all developers to learn about devcontainers and use them consistently. They're super easy to setup and run and would protect from most of what this worm does. https://code.visualstudio.com/docs/devcontainers/containers is the best guide to get started if you use vscode.
  • I've been building an OSS tool to detect software supply-chain attacks: https://github.com/ossillate-inc/packj

    Packj uses static+dynamic code/behavioral analysis to scan for indicators of compromise (e.g., spawning of shell, use of SSH keys, network communication, use of decode+eval, etc). It also checks for several metadata attributes to detect impersonating packages (typo squatting).

  • echo "min-release-age=5" >> ~/.npmrc

    This should be your default minimum if you work with node.

  • You know with all this AGI swirling around nowadays that is stronger than nation state hackers you think one of these companies would demonstrate just how capable they are by defending public infrastructure.

    Unless...

    Maybe in 6 months.

  • yawns Good morning world,

    Here's the updated Antimiasma tool for mitigation [1] [2]. More details on how this tool was built and how the Miasma worm works on my website [3].

    This is the first false flag in the campaign series, where setting the "LANG" environment variable to "ru_RU.UTF-8" or "ru_RU.KOI8-R" won't stop the spreading mechanism.

    So it's likely this could've been any script kiddie that modified the TeamPCP source code dump. It could now also be still APT28/29, that was kind of the purpose of the code dump... to gain plausible deniability :)

    Anyways, stay safe folks.

    [1] https://github.com/cookiengineer/antimiasma

    [2] https://github.com/cookiengineer/antimiasma/releases/tag/mia...

    [3] https://cookie.engineer/projects/cyber-defense/antimiasma.ht...

  • Does anyone happen to have a grep or similar that helps me check if this is showing up anywhere in the trillions of files in node_modules (or pnpm store)?
  • OW. That's gonna leave a mark.

    It sucks that we have this glass-jaw dependency system, which is really the main reason these supply chain attacks work.

    Really hard to clean up, too. These days, you (being the blackhat) would likely send agents to leverage every compromised repo/app/Web site, almost the instant it comes online, so even if the original mess is cleaned up, there's still a ton of knock-on compromises.

  • At this point, any package adding a pre-install hook where there previously was not one should be denied and treated with extreme suspicion.

    It's time pre-install / post-install hooks were killed off. Start with a moratorium on any new ones.

Explore Birbla archives

Keyv and friends compromised in active Shai-Hulud supply chain attack · Birbla