Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
Malicious Postinstall Hook Found in 700 GitHub Repos, Including Node Projects | Better HN
Malicious Postinstall Hook Found in 700 GitHub Repos, Including Node Projects
(opens in new tab)
(socket.dev)
18 points
882542F3884314B
3d ago
4 comments
Share
4 comments
default
newest
oldest
kspetkov79
3d ago
Postinstall hooks are a footgun. The bad part here is that people reviewing a PHP package may not even look closely at package.json.
nullsex
3d ago
Title is somewhat misleading. "Node projects" mean projects using nodejs as opposed to projects under the Node.js org.
tedchs
3d ago
How many more examples of malware postinstall scripts do we need before Node quits running them by default, without warning?
1 more reply
gnabgib
3d ago
All Composer packages (but the malicious part is in the node dependency)
Effected*
> Use effect as a noun to refer to a change resulting from something.
j
/
k
navigate · click thread line to collapse