|
| 1 | +--- |
| 2 | +title: '"No way to prevent this" say users of only package manager where this regularly happens' |
| 3 | +date: 2026-06-01 |
| 4 | +series: "no-way-to-prevent-this" |
| 5 | +type: blog |
| 6 | +hero: |
| 7 | + ai: "Photo by Andrea Piacquadio, source: Pexels" |
| 8 | + file: sad-business-man |
| 9 | + prompt: A forlorn business man resting his head on a brown wall next to a window. |
| 10 | +--- |
| 11 | + |
| 12 | +In the hours following the news that [Redhat Insights' JavaScript packages](https://github.com/RedHatInsights/javascript-clients) fell |
| 13 | +victim to a supply chain attack via NPM, developers and systems administrators |
| 14 | +scrambled ensure all of their projects were unaffected from a supply chain attack that steals credentials for AWS, GCP, Azure, Kubernetes, HashiCorp Vault, npm, and CircleCI before then self-propagating via said stolen npm credentials and the bypass_2fa setting. This establishes persistence via Claude Code hooks and VS Code task injection. If you have installed the affected package, reprovision your development hardware. |
| 15 | +This is is due to the affected dependencies being distributed via |
| 16 | +[NPM](https://www.npmjs.com), the only package manager where these supply-chain |
| 17 | +attacks regularly happen. "This was a terrible tragedy, but sometimes these |
| 18 | +things just happen and there's nothing anyone can do to stop them," said |
| 19 | +programmer Lady Eulah Howell, echoing statements expressed by hundreds of thousands of |
| 20 | +programmers who use the only package manager where 90% of the world's |
| 21 | +supply-chain attacks have occurred in the last decade, and whose projects are |
| 22 | +20 times more likely to fall victim to supply chain attacks. "It's a shame, but |
| 23 | +what can we do? There really isn't anything we can do to prevent supply-chain |
| 24 | +attacks from happening if the maintainers don't want to secure access to their |
| 25 | +accounts in a robust manner". At press time, users of the only package manager |
| 26 | +in the world where these vulnerabilities regularly happen once or twice per |
| 27 | +week for the last year were referring to themselves and their situation as |
| 28 | +"helpless". |
| 29 | + |
| 30 | +For more information, please see upstream documentation published by |
| 31 | +Redhat Insights' JavaScript packages at the following link: [redhat-javascript-clients-06-2026](https://github.com/RedHatInsights/javascript-clients/issues/492). |
0 commit comments