Why in the world would that specific 3x3 matrix be a trigger for an attack? Are they trying to find someone doing some particular kind of numerical analysis?
Presumably it's so it can be used as a subdependency for setting up an attack in a popular, legitimate package, e.g. via a pull request. The code in the legitimate package would not arouse suspicion at all.
Does the FBI or any other law-enforcement office follow up on these backdoors? Is this considered a crime, or even conspiracy to commit a crime, or is it only the act of using the backdoor that's a crime?
We found a remote access implant hidden inside [email protected], an npm package that copies the popular mathjs library.
The NPM package not named in the clickbait-y post title is “mathmain@1.0.0”, for those who run into this particular site obstacle.
Safedep, if you’re reading this, perhaps you should reconsider having that site feature applied to your post — or if it’s something you enabled in, say, Cloudflare, perhaps file a support ticket noting that their email protection is hiding package version strings.
My strategy of not using dependencies at all seems to be getting stronger everyday.
Also no LLM generated skipping this hypetrain completely. Just hand written code I can personally vouch for. Code in exchange for cash, this is professional business, Boss.
Btw, I'm available for hire, preferably by Pre Market Fit or pre-MVP startups, email in profile.
Why in the world would that specific 3x3 matrix be a trigger for an attack? Are they trying to find someone doing some particular kind of numerical analysis?
Presumably it's so it can be used as a subdependency for setting up an attack in a popular, legitimate package, e.g. via a pull request. The code in the legitimate package would not arouse suspicion at all.
Does the FBI or any other law-enforcement office follow up on these backdoors? Is this considered a crime, or even conspiracy to commit a crime, or is it only the act of using the backdoor that's a crime?
I can also see that it's still up in NPM without any warning of any kind: - https://www.npmjs.com/package/mathmain
But the Github repo for the package and the author are down: - https://github.com/allendev12 - https://github.com/allendev12/mathmain
Fascinating how intricate the target selection is on this
The NPM package not named in the clickbait-y post title is “mathmain@1.0.0”, for those who run into this particular site obstacle.
Safedep, if you’re reading this, perhaps you should reconsider having that site feature applied to your post — or if it’s something you enabled in, say, Cloudflare, perhaps file a support ticket noting that their email protection is hiding package version strings.
My strategy of not using dependencies at all seems to be getting stronger everyday.
Also no LLM generated skipping this hypetrain completely. Just hand written code I can personally vouch for. Code in exchange for cash, this is professional business, Boss.
Btw, I'm available for hire, preferably by Pre Market Fit or pre-MVP startups, email in profile.