c/programming · by spez@sh.itjust.works · 152dAxios Supply Chain Attack Pushes Cross-Platform RAT via Compromised npm Account https://thehackernews.com/2026/03/axios-supply-chain-attack-pushes-cross.htmlWhat an ol' classic in the age of AI! 59 points · 3 comments · view on lemmy.world
3 Comments
spez@sh.itjust.works · 18 pts · 152d
TechnoCat@piefed.social · 13 pts · 152d
I always advocate switching to
pnpmwhere install scripts are disabled by default. It has plenty of security features to ward off most supply chain attacks.onlinepersona@programming.dev · 7 pts · 152d
Pre and post install hooks are a mistake, jfk
ultimate_worrier@lemmy.dbzer0.com · -1 pts · 152d