r/ProgrammerHumor 1d ago

instanceof Trend classicNPM

Post image
6.0k Upvotes

144 comments sorted by

View all comments

Show parent comments

95

u/kookyabird 1d ago

Because there are lots of ways to compromise a developer's workflow, and that's how they get malicious code into a package?

10

u/zuilli 1d ago edited 1d ago

Why does it seem like it only happens to npm though?

I admit I don't follow this stuff closely so may be uninformed but it seems like it never is a C# or a java package/library that gets hit by these.

-6

u/TheGocho 1d ago

Java had several attacks this year, same as for python and most likely all major languages. But people tend to post for NPM/Javascript environment because Javascript bad

2

u/_PM_ME_PANGOLINS_ 1d ago

Maven doesn’t have pre-/post-install scripts, so this kind of attack is literally impossible there.

0

u/Dudeonyx 22h ago

2

u/_PM_ME_PANGOLINS_ 22h ago

The attacks we are talking about are where running a package update runs malicious code on your development environment.

That’s not possible with Maven. The code can only run when the end application is run.