Liran Tal 1/26/2019

Open Source From Heaven, Modules From Hell

Read Original

This article examines the hidden security risks of installing npm packages, comparing 'npm install' to piping untrusted scripts into a shell. It explains how package lifecycle scripts can execute arbitrary code and warns against running npm with elevated privileges like sudo, urging developers to be more critical of their dependencies.

Open Source From Heaven, Modules From Hell

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week