Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
awongh
56 days ago
|
parent
|
context
|
favorite
| on:
Cursor 0day: When Full Disclosure Becomes the Only...
I guess this is only specific to a file in the root of the repo, so it doesn't allow for an NPM supply chain attack?
beart
56 days ago
[–]
It has nothing to do with npm. However, a binary could be configured to extract your git/npm secrets using this exploit, which could then lead to a npm supply chain attack (or pip, etc. etc.).
awongh
56 days ago
|
parent
[–]
I meant the attack would be the other way around- if an infected package had the git.exe file in their root.
Or, the infected package could also copy that file into the parent project's root.
beart
56 days ago
|
root
|
parent
[–]
Oh yeah that's a good point - two layers of auto executing scripts/binaries.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: