logoalt Hacker News

Helmut10001today at 4:57 AM0 repliesview on HN

It looks like using Chocolatey [1] saved me from this attack vector because maintainers hardcode SHA256 checksums (and choco doesn't use WinGuP at all).

[1]: https://chocolatey.org/