Massive ChainDrop npm supply-chain attack infects more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry.
Jesus... Here we go again.. as a normal Linux user non dev, do I just not update my PC for now? Until it's known what devs may be compromised downstream?
You're pretty much only at risk on this one if you're doing Javascript development or running a server. The popular Javascript and Python library repos seem to get successfully attacked a couple of times a year each.
Linux main distro repos haven't been reporting any significant breaches. You should be okay to update your system (but if you're on Arch or one of its downstreams, maybe steer clear of AUR packages for now).
Massive ChainDrop npm supply-chain attack infects more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry. | Spyke
4 replies
Jesus... Here we go again.. as a normal Linux user non dev, do I just not update my PC for now? Until it's known what devs may be compromised downstream?
You're pretty much only at risk on this one if you're doing Javascript development or running a server. The popular Javascript and Python library repos seem to get successfully attacked a couple of times a year each.
Linux main distro repos haven't been reporting any significant breaches. You should be okay to update your system (but if you're on Arch or one of its downstreams, maybe steer clear of AUR packages for now).
It feels like this shit happens weekly. Dont worry about it. Let the upstream nerds sort it out in their build process.
Oh, sh*t...