Fuck paper bitcoin summer, this is supply chain attack summer.

Reply to this note

Please Login to reply.

Discussion

lol, indeed!

I am fixing 4 moderate severity vulnerabilities on vite js / plugin react ., is that connect with the the post above

Nope. post above is about Rust crates, but there have been a huge number of similar attacks on npm packages recently too.

NPM

Package mostly installed from

Git hub repo , and sometimes they show you , like 4 moderate vulnerabilities until 3 severe vulnerability for example … always be cautions and careful to download . Sometimes there is so much version deprecated ⚠️