Skip to content
Better HN
Top
Best
Ask
Show
New
Jobs
Search
⌘K
Malicious Postinstall Hook Found in 700 GitHub Repos, Including Node Projects
(opens in new tab)
(socket.dev)
18 points
882542F3884314B
1mo ago
4 comments
Save
Share
4 comments
4 comments · 4 top-level
top
newest
oldest
kspetkov79
1mo ago
Postinstall hooks are a footgun. The bad part here is that people reviewing a PHP package may not even look closely at package.json.
nullsex
1mo ago
Title is somewhat misleading. "Node projects" mean projects using nodejs as opposed to projects under the Node.js org.
tedchs
1mo ago
How many more examples of malware postinstall scripts do we need before Node quits running them by default, without warning?
1 more reply
gnabgib
1mo ago
All Composer packages (but the malicious part is in the node dependency)
Effected*
> Use effect as a noun to refer to a change resulting from something.
j
/
k
navigate · click thread line to collapse