altairprime 35 minutes ago

> We found a remote access implant hidden inside [email protected], an npm package that copies the popular mathjs library.

The NPM package not named in the clickbait-y post title is “mathmain@1.0.0”, for those who run into this particular site obstacle.

Safedep, if you’re reading this, perhaps you should reconsider having that site feature applied to your post — or if it’s something you enabled in, say, Cloudflare, perhaps file a support ticket noting that their email protection is hiding package version strings.

  • QuantumNomad_ 19 minutes ago

    Probably Cloudflare. For me it shows the package name rather than a redaction. But from memory, Cloudflare email protection redacts it that way in the HTML and then adds a little JS to put it back in which might also do some kind of check to see if it thinks you are a real user before unredacting it.

j2kun 51 minutes ago

Why in the world would that specific 3x3 matrix be a trigger for an attack? Are they trying to find someone doing some particular kind of numerical analysis?

  • zarzavat 46 minutes ago

    Presumably it's so it can be used as a subdependency for setting up an attack in a popular, legitimate package, e.g. via a pull request. The code in the legitimate package would not arouse suspicion at all.

  • tranceylc 20 minutes ago

    I would assume it’s actually so they can allow it to spread before it gets activated. Then do something that affects the entire chain of package dependencies

nextzck 38 minutes ago

Fascinating how intricate the target selection is on this

TZubiri 32 minutes ago

My strategy of not using dependencies at all seems to be getting stronger everyday.

Also no LLM generated skipping this hypetrain completely. Just hand written code I can personally vouch for. Code in exchange for cash, this is professional business, Boss.

Btw, I'm available for hire, preferably by Pre Market Fit or pre-MVP startups, email in profile.

  • iLoveOncall 8 minutes ago

    Let us know in 2838 when you finish your first program, would love to check it out!