zlacker

[parent] [thread] 1 comments
1. chii+(OP)[view] [source] 2026-02-04 06:57:01
Why wouldn't those also become a target, if they would grow to be sizable?

And if they have prevention mechanisms, why can't existing supply chains be secured with similar prevention mechanisms, instead of funneling to a single package manager provider?

replies(1): >>kijin+7h
2. kijin+7h[view] [source] 2026-02-04 09:18:04
>>chii+(OP)
The supply chain for Notepad++ updates was a PHP script on a shared hosting account pointing to the URL of an executable file.

Surely someone with more resources and more sets of eyes could do better than that? AFAIK nobody has compromised Debian's APT repositories and Red Hat's RPM repositories yet.

[go to top]