NPM packages are getting hacked

แชร์
ฝัง
  • เผยแพร่เมื่อ 28 ม.ค. 2025

ความคิดเห็น • 83

  • @beeeeeee42333
    @beeeeeee42333 3 ปีที่แล้ว +22

    Being a Penetration tester for years and answering such wild topic is next level for me :) , but this guys makes everything feel forget about it :)

  • @subhamadhikari
    @subhamadhikari 3 ปีที่แล้ว +1

    The way you deliver information has evolved and I wasn't expecting this way. Anyway liked it ❤

  • @saikatmukherjee6962
    @saikatmukherjee6962 3 ปีที่แล้ว +16

    This Video is Only Expected from Hitesh Sir, Love the way U teach 👏 🙌 One stop Solution to Everything Hitesh Choudhary

    • @HiteshCodeLab
      @HiteshCodeLab  3 ปีที่แล้ว +1

      Thanks 😁

    • @kapilkumar-rk8fe
      @kapilkumar-rk8fe 3 ปีที่แล้ว

      @@HiteshCodeLab could you tell me the name of the song, l like that

    • @Akira-sh7ts
      @Akira-sh7ts 3 ปีที่แล้ว

      @@kapilkumar-rk8fe ++

  • @mrvaibh0
    @mrvaibh0 3 ปีที่แล้ว +3

    1:12 please tell about this... who writes these papers? what actually it contains? and how to be a part of it? (as a developer)
    please help through

  • @codenamegrant
    @codenamegrant 3 ปีที่แล้ว

    This was incredible. Thanks. Gonna look at some of your courses now.

  • @KRoc
    @KRoc 3 ปีที่แล้ว +3

    Maybe a Vericode scan could be included and if passing, append a '.vta' (vericode tested & approved) extension to the end of the version. And have the ability in the package.json to only pull in libraries with the .vta extension? Probably some issues with this, but I'd be more confident if I knew the libraries were scanned.

  • @dhanushholla9221
    @dhanushholla9221 3 ปีที่แล้ว +1

    💯🔥spicy video 😂+informative .. hacker Hitesh 🤣

  • @karanparmar4318
    @karanparmar4318 3 ปีที่แล้ว

    can you explain what `npm audit fix` command does in brief ?

  • @ajayantu
    @ajayantu 3 ปีที่แล้ว +1

    Sir I have taken your mern course..do I need the full backend course ?

  • @solutionstack6413
    @solutionstack6413 3 ปีที่แล้ว +1

    If this happens in the future, how do we fix things in our package?
    Just npm install 🤔?

  • @shaikmansoor1868
    @shaikmansoor1868 3 ปีที่แล้ว +3

    Now I understood why all of our team were running behind updating ua-parser-js version in our project last week...

  • @krishnachaitanya8194
    @krishnachaitanya8194 3 ปีที่แล้ว

    Just curious to know why don't we have security in place before pushing any package just like the app store which accepts only if everything is fine? If it is because so many packages per day then if security comes in place authors will also be mindful in publishing as it takes time to get published.

  • @shobhithap799
    @shobhithap799 3 ปีที่แล้ว +1

    Hi Hitesh , can you make video on how to write test cases in react js

  • @futureprogress
    @futureprogress 3 ปีที่แล้ว +1

    Yeah, learning about these NPM exploits made me decide to use a VM for all local development. The other issue is NPM security warnings in CLI feel useless right now.

    • @futureprogress
      @futureprogress 3 ปีที่แล้ว

      @Contact From what understand WSL does minimize the attack surface but is still less secure than a full VM

  • @Akira-sh7ts
    @Akira-sh7ts 3 ปีที่แล้ว

    Outro song ?

  • @arieheinrich3457
    @arieheinrich3457 3 ปีที่แล้ว

    similar to half a year or more ago with the a different public library heavily used, with a difference that the owner of the library wanted to move maintainer role to someone else as he couldnt continue and the person he gave the trust in had malicious intent, so no hacking to the npm publishing profile was made. ANY dependencies, doesnt have to be npm, are a double edge swords', they make it easier to create software but require huge amounts of trust that is sometimes misplaced. If doesnt have to be ill intent people, just read about the left-pad incident to understand the level of trust were dealing with

  • @strikerftw8729
    @strikerftw8729 3 ปีที่แล้ว +5

    Angular & React Developers left the chat 😂

  • @UdayKumar-xr2me
    @UdayKumar-xr2me 3 ปีที่แล้ว

    Need to have verified tag for packages.. and hash verification of packages can be done

  • @AmitK
    @AmitK 3 ปีที่แล้ว

    Hitesh , I like your metalic t-shirt , I was trying to find it , please tell me where did you get it , it seems pretty light weight

  • @sagniksaha4179
    @sagniksaha4179 3 ปีที่แล้ว +4

    Really a important video I also use a lot of npm packages and I think we should always know about their security

  • @robokishan
    @robokishan 3 ปีที่แล้ว

    There is debit card on your desk .? Logo looks like of hdfc bank visa card

  • @komal6816
    @komal6816 3 ปีที่แล้ว

    Cute how you brought about your suggestion of subscribing to your channel 😀

  • @mohammedrihan839
    @mohammedrihan839 3 ปีที่แล้ว

    Do this course for back end web development?

  • @mohammedrihan839
    @mohammedrihan839 3 ปีที่แล้ว

    Do you have any full stack web development course?

  • @kuku687
    @kuku687 3 ปีที่แล้ว

    Very informative, thanks Hitesh for this.

  • @NithinKVarrier
    @NithinKVarrier 3 ปีที่แล้ว +2

    Card on the desk. Security 😜

    • @HiteshCodeLab
      @HiteshCodeLab  3 ปีที่แล้ว +2

      Hahaha, that’s a dummy card to test

  • @harshitagupta189
    @harshitagupta189 3 ปีที่แล้ว

    You came up with spicy information video not just spicy video 😅..

  • @avgaming7317
    @avgaming7317 3 ปีที่แล้ว +1

    Truly said 👏 💯

  • @jsdepth
    @jsdepth 3 ปีที่แล้ว +1

    Make a video on Remix framework

  • @arjayarjay8856
    @arjayarjay8856 3 ปีที่แล้ว

    Thanks for sharing the news

  • @deepa5254
    @deepa5254 3 ปีที่แล้ว

    Hi Hitesh sir. Can you make a tutorial on apache wicket framework? Or can you provide any material please?? Thanks

  • @elamandeep
    @elamandeep 3 ปีที่แล้ว +2

    Your thumbnail is awesome

  • @ganeshtak4445
    @ganeshtak4445 3 ปีที่แล้ว

    these attacks are happing because Microsoft has an offer of a 25k $ price pool, anybody who found a vulnerability in the npm package, one of my friends is also doing this.

  • @bhargavpandya9189
    @bhargavpandya9189 3 ปีที่แล้ว

    This is scary AF!

  • @ashwinir5110
    @ashwinir5110 3 ปีที่แล้ว

    Please make videos on application security

  • @raviyadav2552
    @raviyadav2552 3 ปีที่แล้ว

    this give me chills

  • @abhishekchaudhary8965
    @abhishekchaudhary8965 3 ปีที่แล้ว

    This is so spicy 🔥😍😍

  • @vatsalyasinghi438
    @vatsalyasinghi438 3 ปีที่แล้ว

    Can't comprehend what sort of havoc would be caused if such attacks happen to libraries like moment js, lodash or rxjs .. holy shit 😅

  • @robertwalker2446
    @robertwalker2446 3 ปีที่แล้ว

    I like how our security advisor Hitesh leaves his visa card on the desk while filming. Intentional? :P

  • @akitibala7180
    @akitibala7180 3 ปีที่แล้ว

    Tools like synk might be help this

  • @saeedtalib8358
    @saeedtalib8358 3 ปีที่แล้ว +1

    It was getting hacked by day one
    No matter people like us got it now

  • @UdayKumar-xr2me
    @UdayKumar-xr2me 3 ปีที่แล้ว

    Please make a course on web app security. It would be very helpful to a lot many.

  • @Meckdenis
    @Meckdenis 3 ปีที่แล้ว

    That's why DENO came in to picture

  • @secureitmania
    @secureitmania 3 ปีที่แล้ว

    Dependency Confusion attacked

  • @abhisheksanjaygawade1479
    @abhisheksanjaygawade1479 3 ปีที่แล้ว +1

    Does Django is solutions for npm

  • @JobinSelvanose
    @JobinSelvanose 3 ปีที่แล้ว

    atm card on the desk 😅😁

  • @gouravkumarnath6476
    @gouravkumarnath6476 3 ปีที่แล้ว +1

    I hope this is there in backend development course

  • @saurabhsrivastav3012
    @saurabhsrivastav3012 3 ปีที่แล้ว +1

    Sab krlo hum first hum first

  • @peacefrog1938
    @peacefrog1938 3 ปีที่แล้ว

    Guess i'll use yarn

  • @dheerajnagar9742
    @dheerajnagar9742 3 ปีที่แล้ว

    Before write first please refresh your comment box...

  • @imkir4n
    @imkir4n 3 ปีที่แล้ว

    I always think about these

  • @oneito947
    @oneito947 3 ปีที่แล้ว

    deno tries to solve that

  • @hypergraphic
    @hypergraphic 3 ปีที่แล้ว

    I’m seriously thinking of making a new git repo just for dependencies that have been audited and adding it as a sub module where needed. It’s definitely going to make me think really hard about adding a new dependency.

  • @chinmayhotshot
    @chinmayhotshot 3 ปีที่แล้ว

    Otp before uploading

  • @sandeep87raju
    @sandeep87raju 3 ปีที่แล้ว +1

    Thanks Hitesh for the informative video. I wish no hacker is able to get data of your hdfc visa card that is kept on the table. 😁

  • @rishiraj9131
    @rishiraj9131 3 ปีที่แล้ว

    🙏 Good day

  • @StayAware9
    @StayAware9 3 ปีที่แล้ว +3

    Your credit card is kept on the table, cropped the image and cleared it using one of the ML tool
    card number and expiry date is exposed by you
    You should care more about your security than NPM's

  • @ManishJangir
    @ManishJangir 3 ปีที่แล้ว

    Unfortunately we also became the victim of this hijacking. Our private npm registry cached that package within those 20 mins before NPM itself actually removed the compromised versions.

  • @anirudhcodes
    @anirudhcodes 3 ปีที่แล้ว

    npm install security

  • @adeshmahatme1988
    @adeshmahatme1988 3 ปีที่แล้ว

    your card sir

  • @martinmachua
    @martinmachua 3 ปีที่แล้ว

    You have an npm crash course,😂 and npm has been crashed already!!

  • @user-bu6pf4dd6y
    @user-bu6pf4dd6y 3 ปีที่แล้ว

    Fastest confirmation 🔝👍 believe me no one ☝️ does it better than this , best and fast

  • @errorcode0101
    @errorcode0101 3 ปีที่แล้ว

    You are from spin the hack

  • @yashpandey350
    @yashpandey350 3 ปีที่แล้ว +1

    666k subs😜😜😜😜😜

  • @dheerajnagar9742
    @dheerajnagar9742 3 ปีที่แล้ว

    The new way.... To hack😁

    • @Ghulatz
      @Ghulatz 3 ปีที่แล้ว

      By machines,

  • @Ahmad-qy8ze
    @Ahmad-qy8ze 3 ปีที่แล้ว

    love from Pakistan

  • @BhuveshDhiman
    @BhuveshDhiman 3 ปีที่แล้ว

    😀

  • @vikassrivastava6017
    @vikassrivastava6017 3 ปีที่แล้ว

    🥈

  • @khizrshaikh9902
    @khizrshaikh9902 3 ปีที่แล้ว +1

    First

  • @user-bu6pf4dd6y
    @user-bu6pf4dd6y 3 ปีที่แล้ว

    Fastest confirmation 🔝👍 believe me no one ☝️ does it better than this , best and fast

  • @kvs123100
    @kvs123100 3 ปีที่แล้ว

    First

  • @Pk-ut2ge
    @Pk-ut2ge 3 ปีที่แล้ว

    First

  • @amenakevwe6007
    @amenakevwe6007 3 ปีที่แล้ว

    First