logoalt Hacker News

throwwwlltoday at 1:51 PM2 repliesview on HN

And all of them "thought" of security as an after-after-after-after-after-thought.


Replies

freakynittoday at 1:55 PM

Most of these are now building upon techniques that have already been exploited since past 1 years. This attack used 4 of those techniques.

1. Lifecycle Hook Execution

2. CI/CD Identity Plane Attacks

3. Maintainer Account Takeover and Malicious Publish

4. Self-Replicating npm Worms

https://npm-supply-chain-attack-techniques.pagey.site/

show 1 reply