Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

This is malware #1

Open
qpwo opened this issue Mar 14, 2022 · 6 comments
Open

This is malware #1

qpwo opened this issue Mar 14, 2022 · 6 comments

Comments

@qpwo
Copy link
Owner

qpwo commented Mar 14, 2022

this is malware

@icyJoseph
Copy link

Do you have any link, or source to check this claim?

NPM recently removed the ability for users to report compromised packages

Because it looks to me like I could, if I wanted, report the package.

@mlugg
Copy link

mlugg commented Mar 15, 2022

Yeah, I'm also confused; this "Report malware" button exists pretty clearly on the package page, and this doc page says that it'll go to "the npm security team" (whoever that is)
image

@qpwo
Copy link
Owner Author

qpwo commented Mar 15, 2022

Do you have any link, or source to check this claim?

Last couple times I went to report a security problem I got a prompt "Are you a maintainer of this package?" and I hit no then it said go home

@qpwo
Copy link
Owner Author

qpwo commented Mar 15, 2022

Oh it looks like they took it down 🎉

@varunsh-coder
Copy link

@qpwo thanks for creating this to raise awareness of the problem. I have been working on the problem of detecting outbound traffic for this exact scenario, and while detecting from a desktop is hard, this new GitHub Action does allow detecting and restricting outbound traffic from GitHub Actions workflows that run on GitHub-hosted runner.

https://github.com/step-security/harden-runner

@qpwo
Copy link
Owner Author

qpwo commented Mar 19, 2022

Brilliant I'll probably add a proper "tooling recommendations" section to the readme at some point and I'll add that to it

Repository owner deleted a comment from tim-tepia Mar 18, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants