Popular 'coa' NPM library hijacked to steal user passwords

This page summarizes the projects mentioned and recommended in the original post on /r/programming

Our great sponsors
  • InfluxDB - Power Real-Time Data Analytics at Scale
  • WorkOS - The modern identity platform for B2B SaaS
  • SaaSHub - Software Alternatives and Reviews
  • rfcs

    Public change requests/proposals & ideation (by npm)

  • It's really a problem that needs to be addressed. We desperately need something like https://github.com/npm/rfcs/issues/480 or https://github.com/npm/rfcs/discussions/80.

  • crates.io

    The Rust package registry

  • I hope that other languages with similar OSS ecosystems take note - I'm looking at you, crates.io - and incorporate some kind of crowd-sourced auditing or something.

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
  • cargo-crev

    A cryptographically verifiable code review system for the cargo (Rust) package manager.

  • It exists.

  • cryptography

    cryptography is a package designed to expose cryptographic primitives and recipes to Python developers.

  • You don't get the benefit of "security" by using version ranges. If anything, your builds must produce same result whether they're built a year later, tomorrow, or next month, when built from same source configuration. In fact, it's less secure because you might get an update that breaks entire API or builds (See: cryptography library update breaking entire ecosystem. a library that must be as stable as possible. What if it packaged malware instead?)

  • feedback

    Public feedback discussions for npm (by npm)

  • There is an ongoing discussion about 2FA and possible bandaids for this sort of problem in the npm community forum: https://github.com/npm/feedback/discussions/588

  • deno

    A modern runtime for JavaScript and TypeScript.

  • https://deno.land is an alternative server-side JS runtime that is sandboxed by default.

  • typometer

    Text / code editor typing latency analyzer

  • WorkOS

    The modern identity platform for B2B SaaS. The APIs are flexible and easy-to-use, supporting authentication, user identity, and complex enterprise features like SSO and SCIM provisioning.

    WorkOS logo
NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts