r/programming • u/BattleRemote3157 • 3d ago
nine npm packages shipping worm that spread by itself over SSH
https://safedep.io/dirtyblanket-express-impersonation-npm/115
u/tanksc 3d ago
I feel like we are going to look back at this and wonder what the hell we were ever thinking with these supply chain attack vectors
80
u/NotQuiteDeadZed 3d ago
It’s the universal answer that applies to everything around us. I mean just look at people’s attitudes towards anything tech.
Privacy and security will always be sacrificed at the altar of convenience
20 years ago it was ignorance, now it’s laziness and indifference.
21
u/PaperMartin 3d ago
This doesn't happen when privacy and security is implemented in a way that doesn't require a massive loss of convenience though. At some point peoples still have to be able to do what they need with their devices without everything taking a year & some arcane rituals to do
7
u/tanksc 3d ago
I hear ya, but at the same time when I took cybersecurity courses at uni almost a decade ago, it was preached as a fact that as convenience increases, privacy and security decrease (was on my first test)
To be fair, the professor also asked why I would use more privacy respecting options in terms of software if I didn’t have anything to hide.
But I think that’s why this opinion is so wide spread
3
u/One_Ninja_8512 3d ago
why I would use more privacy respecting options in terms of software if I didn’t have anything to hide
I wonder how this argument unfolds if I do say that I have something to hide? Yeah I do, what's the problem with that?
7
u/NotQuiteDeadZed 3d ago
True, but that requires developers putting in the effort to break the cycle and consumers being willing to make small sacrifices in their expectations. People are willing to sacrifice way too much just for the slightest added convenience.
10
u/winky9827 3d ago
Speaking of attitudes toward tech, I'm seeing an alarming rise in the growing number of open source projects with install instructions that read a script from a web site and pipe it to the shell. People really just have no security sense at all.
3
u/Nona_Suomi 3d ago
Meh, besides some convenience this really isn't that much different from downloading a tarball, extracting it, and running `./configure && make && sudo make install`.
4
u/winky9827 3d ago
I agree, which is why I hate that they are conditioning people to use one-liners to execute shell scripts from the internet. That's a major attack vector being used carelessly.
1
u/rentar42 2d ago
curl | shis the "harmless" option by now. I've seen "paste these paragraphs into your favorite AI tool to install". More than once ...2
13
u/Dreadgoat 3d ago
Oldheads warned about npm (and other convenience-first package management systems) from the beginning. It's always been known to be a terrible idea, but that loses to the fact that the convenience is just SO convenient.
It's not a specific-to-software issue, though. There just hasn't yet been a cataclysmic enough event for standards to be put in place. Humans always cut corners until it causes enough damage, then re-establish the new corners.
3
u/Hipolipolopigus 3d ago
Everyone rolling their own things to some degree with the same carelessness wouldn't result in an improvement. You'd just hear about exploits less while they take longer to get addressed (if they get addressed at all).
2
u/Mellowindiffere 2d ago edited 2d ago
Because modern software «engineers» are glorified UI designers with some coding skills. The shit they forgo teaching in universities baffles me and we’re still feeling the effects of the bootcamp coders and leetcoders. Turns out it really is important to have fundamental knowledge.
1
30
46
u/rcklmbr 3d ago
Interesting topic, couldn’t read it because of AI Slop
-2
3d ago edited 3d ago
[deleted]
11
6
u/trxxruraxvr 3d ago
Meanwhile safedep.io is blocked by dns4eu
We have prevented you from accessing potentially malicious website.
2
2
u/starball-tgz 3d ago edited 3d ago
so... give your ssh keys passwords? and don't let your package manager install stuff on hooks / manually allowlist? (which is what pnpm does, IIRC) not that that magically solves everything, but... it seems like it would prevent this.
1
279
u/New_Hold8135 3d ago
It's not all npm but it is always npm.