• 0 Posts
  • 18 Comments
Joined 26 days ago
cake
Cake day: February 3rd, 2026

help-circle

  • This article talks about “typosquating”, that just means they introduced packages with a similar name to other packages but in this case also containing malicious code.

    I expect other package managers to be just as vulnerable to this. The only way I can think of to mitigate this is very strict registry policies, someone checking all version of all packages in the registry to make sure there is no malicious code in them. That would take a lot of effort.

    I think the biggest problem with npm is just that it is very popular, so for attackers the chance of hitting something with their attack is bigger than with other systems.

    I don’t believe yarn is any more secure than npm, especially not for this type of attack. Yarn used to be a bit more secure because it checked checksums where npm didn’t, but that has been added to npm as well now (https://sebhastian.com/npm-err-code-eintegrity/)















  • Yeah so this wasn’t easy for the Netherlands either. They just started trying earlier, so they had more time to fail and try again. This would maybe not fly anymore in a newly designed street in the NLs now, but it sure as heck looks a lot like some older roads in the Hague that are still waiting on their update to the new guidelines.

    So well done guys, you are def. going in the right direction with this 🙏.

    The only thing you could maybe argue is why they are not just asking for a bit of help from a Dutch road designer during the design process. I mean, the knowledge is all there already, why not use it? 😉