• TechnoCat@piefed.social
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 hours ago

    On closer inspection, preventing post-install would have fixed it too: “The attack exploited a transitive dependency, plain-crypto-js@4.2.1, which executed a postinstall script to deploy the RAT.”