Skip to content

Commit 7346b96

Browse files
committed
chore: no way to prevent this yet again
Signed-off-by: Xe Iaso <me@xeiaso.net>
1 parent 298b5a3 commit 7346b96

1 file changed

Lines changed: 31 additions & 0 deletions

File tree

Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
---
2+
title: '"No way to prevent this" say users of only package manager where this regularly happens'
3+
date: 2026-06-01
4+
series: "no-way-to-prevent-this"
5+
type: blog
6+
hero:
7+
ai: "Photo by Andrea Piacquadio, source: Pexels"
8+
file: sad-business-man
9+
prompt: A forlorn business man resting his head on a brown wall next to a window.
10+
---
11+
12+
In the hours following the news that [Redhat Insights' JavaScript packages](https://github.com/RedHatInsights/javascript-clients) fell
13+
victim to a supply chain attack via NPM, developers and systems administrators
14+
scrambled ensure all of their projects were unaffected from a supply chain attack that steals credentials for AWS, GCP, Azure, Kubernetes, HashiCorp Vault, npm, and CircleCI before then self-propagating via said stolen npm credentials and the bypass_2fa setting. This establishes persistence via Claude Code hooks and VS Code task injection. If you have installed the affected package, reprovision your development hardware.
15+
This is is due to the affected dependencies being distributed via
16+
[NPM](https://www.npmjs.com), the only package manager where these supply-chain
17+
attacks regularly happen. "This was a terrible tragedy, but sometimes these
18+
things just happen and there's nothing anyone can do to stop them," said
19+
programmer Lady Eulah Howell, echoing statements expressed by hundreds of thousands of
20+
programmers who use the only package manager where 90% of the world's
21+
supply-chain attacks have occurred in the last decade, and whose projects are
22+
20 times more likely to fall victim to supply chain attacks. "It's a shame, but
23+
what can we do? There really isn't anything we can do to prevent supply-chain
24+
attacks from happening if the maintainers don't want to secure access to their
25+
accounts in a robust manner". At press time, users of the only package manager
26+
in the world where these vulnerabilities regularly happen once or twice per
27+
week for the last year were referring to themselves and their situation as
28+
"helpless".
29+
30+
For more information, please see upstream documentation published by
31+
Redhat Insights' JavaScript packages at the following link: [redhat-javascript-clients-06-2026](https://github.com/RedHatInsights/javascript-clients/issues/492).

0 commit comments

Comments
 (0)