Active supply chain attack against NPM #1429
Malexandra-de
started this conversation in
General
Replies: 1 comment
|
Thank you for the heads up. I appreciate your vigilance! 💪 Due to my field of work, the security of this container is first and foremost, and I am tracking this attack. This morning's build of the container (24 minutes ago) shows no detected vulnerabilities in the dependencies. You can view the two different types of reports directly in GitHub: The container alone: The container with FoundryVTT installed: Thank you again. Please continue to feel free to ping me whenever you have a security concern about the container. If you find a vulnerability you can report it here: |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Right now there's an active attack aimed at stealing credentials and compromising npm packages.
https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised
This can apparently be exploited by running gitlab pipelines pulling compromised versions, so this project might be vulnerable.
All reactions