Keyv and friends compromised in active Shai-Hulud supply chain attack

aikido.dev

207 points by cimi_ 10 hours ago


atechboy - 2 minutes ago

what commercial tools are enterprises using today to defend against such attacks? Do they really work? I mean, do they report/block malware after the fact or detect proactively. Because if the latter then, package registries should really be removing reported packages, right?

xnorswap - 7 hours ago

At this point, any package adding a pre-install hook where there previously was not one should be denied and treated with extreme suspicion.

It's time pre-install / post-install hooks were killed off. Start with a moratorium on any new ones.