zlacker

[parent] [thread] 1 comments
1. hypeat+(OP)[view] [source] 2026-02-02 11:55:03
Integrity checks say nothing about the package authenticity, though. State sponsored actors could just... change the hash on the listing in a hypothetical attack.
replies(1): >>Lammy+It1
2. Lammy+It1[view] [source] 2026-02-02 20:04:24
>>hypeat+(OP)
“Just” lol

That would be two things that would have to be compromised and redirected simultaneously to malicious versions. Way more likely to be noticed too because one of them would be GitHub, and unless they mirror the entire rest of the package metadata index and keep it up to date for everything else besides their targeted malicious package.

[go to top]