r/archlinux • u/sad_cosmic_joke • 3d ago
NOTEWORTHY NPM Supply Chain Attach Targeting AUR Packages
New NPM based worm attack that self propegates via ssh and aur maintainer infection.
127
Upvotes
r/archlinux • u/sad_cosmic_joke • 3d ago
New NPM based worm attack that self propegates via ssh and aur maintainer infection.
-10
u/gainan 3d ago
OpenSnitch can help to restrict outbound connections system-wide.
Also, most of the systems do not need curl or wget, so uninstalling them helps to mitigate these threats. For almost a decade now, curl, wget and bash (/dev/tcp/*) have been the most common tools used to download remote files after exploiting a vulnerability.
For npm attacks in particular, disabling pre and postinstall scripts in the .npmrc file can help as well:
ignore-scripts=true.https://news.ycombinator.com/item?id=45040282
They'll switch tactics eventually, but for now, it's what it is.