ossf / package-analysis

Open Source Package Analysis
Apache License 2.0
720 stars 48 forks source link

Crypto Miner Attack #111

Closed naveensrinivasan closed 1 year ago

naveensrinivasan commented 2 years ago

The package analysis should capture and warn about this kind of attack https://github.com/faisalman/ua-parser-js/issues/536

DanielRuf commented 2 years ago

The maintainer probably did not enforce 2FA for npm releases on npmjs.com.

calebbrown commented 1 year ago

147 would solve this issue, as might #97.

Closing as this is about a specific example.