Julien M. · @julm
486 followers · 4935 posts · Server framapiaf.org


> The Open Source Security Foundation () has announced the initial prototype release of a new that's capable of carrying out dynamic of all packages uploaded to popular repositories.
> In a test run that lasted a month, the tool identified more than 200 malicious packages uploaded to and , with a majority of the rogue libraries leveraging and attacks.
thehackernews.com/2022/05/here

#typosquatting #DependencyConfusion #npm #pypi #opensource #analysis #tool #OpenSSF #supplychain #infosec

Last updated 2 years ago

Antonio Hdez. Blas 🔵 · @nihilipster
105 followers · 264 posts · Server fosstodon.org

"In this post, I demonstrate that critical parts of the package management system are vulnerable to the supply chain attack."

frasertweedale.github.io/blog-

#haskell #hackage #DependencyConfusion #security #cabal

Last updated 4 years ago