• platypus_plumba@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      9 months ago

      It’s honestly crazy that tools like npm don’t force you to encrypt the tokens for the npm repos. They don’t even support it. Any stupid read_file() with http.post() can screw 1000 people.

  • ShaunaTheDead@kbin.social
    link
    fedilink
    arrow-up
    7
    arrow-down
    3
    ·
    9 months ago

    This feels like a great application of AI to root around through the code of packages in these repos and find ones that access the ssh key directory at all to be looked at more thoroughly by a human.

    • CmdrKeen@lemmy.today
      link
      fedilink
      arrow-up
      4
      ·
      9 months ago

      IDK, virus scanners and malware detectors could do these things before AI.

      You could search for stuff like directly accessing the ~.ssh directory, or any invocations of wget or curl to download external scripts and run them through an interpreter and flag those for closer inspection.

      If you want to get fancier, automate installing packages in an isolated environment (like a container or VM) and keep track of every file system access and network request they make.

      Sure, eventually they’ll figure out ways to obfuscate those things, too, but it could at least prevent people from doing things in such blatantly obvious ways.

    • blargerer@kbin.social
      link
      fedilink
      arrow-up
      19
      ·
      9 months ago

      Its just a weird word choice for many/a group. If you read the article they are typo squatting legitimate packages with alternate versions that steal the ssh keys.