Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

npm ua-parser-js hijack #4

Closed
vielmetti opened this issue Oct 22, 2021 · 10 comments
Closed

npm ua-parser-js hijack #4

vielmetti opened this issue Oct 22, 2021 · 10 comments

Comments

@vielmetti
Copy link

report this a.m. of https://www.npmjs.com/package/ua-parser-js being hijacked in NPM - I don't have much more in the way of details yet.

@vielmetti
Copy link
Author

some detail on https://snyk.io/vuln/npm:ua-parser-js

@vielmetti
Copy link
Author

@vielmetti
Copy link
Author

The relevant issue from Github faisalman/ua-parser-js#536

@adityasaky
Copy link
Owner

All of this looks very relevant, thanks! I'll shortly either update it here or at https://github.com/cncf/tag-security/tree/main/supply-chain-security/compromises. This reminds me of event-stream, which is already listed there. Going by faisalman/ua-parser-js#536 (comment)

@adityasaky
Copy link
Owner

Tracking it here: cncf/tag-security#812

@adityasaky
Copy link
Owner

Thanks for bringing it up here! Did you hear of it from a particular channel / mailing list etc? Because if so, I'd like to join it and keep an eye out for other instances.

@adityasaky
Copy link
Owner

Closing in favour of the tag-security thread.

@vielmetti
Copy link
Author

I heard about it from a channel in my coworking space's Slack - not a dedicated security channel.

@adityasaky
Copy link
Owner

Gotcha. Thank you!

@vielmetti vielmetti mentioned this issue Nov 4, 2021
Closed
@adityasaky
Copy link
Owner

cncf/tag-security#812

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants