Hacker Newsnew | past | comments | ask | show | jobs | submit | chillax's commentslogin

Companies such as socket and safedep will still scan new packages and alert on malware (if they are able to detect it) so the packages are taken down before they pass your cool down


It’s kind of insane this doesn’t happen in the publish pipeline by default.


This is what serious software distribution platforms do. Developers may think that they are special and they would never install malware, but that's just not the case.



Related: Someone Knows Bash Far Too Well, And We Love It (Ivanti EPMM Pre-Auth RCEs CVE-2026-1281 & CVE-2026-1340) https://labs.watchtowr.com/someone-knows-bash-far-too-well-a...


I think there is an easier substitution attack since there is shell expansion occuring. I will toy with it later today.


The array indexing thing is a special case in [[...]] which is otherwise more-or-less secure (no expansion occurs under typical unquoted variable access). https://news.ycombinator.com/item?id=46631811



Considering the sheer number of commercial flight routes and travel demand worldwide, that actually sounds pretty promising.


According to Aikido Security the attack has now targeted 180+ packages: https://www.aikido.dev/blog/s1ngularity-nx-attackers-strike-...


Possible the UK version of this? https://vat-one-stop-shop.ec.europa.eu/index_en



A better link would be the dedicated site for it, also contains introduction which describes what NHI are: https://owasp.org/www-project-non-human-identities-top-10/20...


Ok, we've changed to that from https://owasp.org/www-project-non-human-identities-top-10/. Thanks!


Here is how OWASP define it:

> Non-human identities (NHIs) are used to provide authorization to software entities such as applications, APIs, bots, and automated systems to access secured resources. Unlike human identities, NHIs are not controlled or directly owned by a human. Their identity object and authentication often work differently to human, and common human user security measures do not apply to them.

https://owasp.org/www-project-non-human-identities-top-10/20...



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: