logoalt Hacker News

lrvicktoday at 1:38 AM2 repliesview on HN

This could for instance be injected into your .bashrc when you do an "npm install" of a package that has a deeply nested supply chain attack.

Then the next time you run sudo, phase2 triggers installing a rootkit, etc.


Replies

arcfourtoday at 1:57 AM

Or you could also hijack it using $PATH search order with your wrapper to get existing terminal sessions too, there's a lot of ways to skin that cat.

show 1 reply
Ferret7446today at 2:15 AM

That is one of many reasons to keep your dotfiles under version control.

show 2 replies