Building a Supply Chain Attack with .NET and NuGet
A developer explores how to build a .NET supply chain attack using NuGet, module initializers, and source generators, highlighting security risks.
A developer explores how to build a .NET supply chain attack using NuGet, module initializers, and source generators, highlighting security risks.
A critique of JavaScript's dependency management after a major supply-chain attack, arguing for systemic change but predicting stagnation.
A technical exploration of how .NET, NuGet, and other tools can be exploited to create a software supply chain attack, using a demo package as an example.
A detailed analysis of the malicious event-stream npm package backdoor, its timeline, and the social engineering attack that led to its inclusion.