Video of malware node packages trying to phone home

This page summarizes the projects mentioned and recommended in the original post on /r/Malware

Our great sponsors
  • SurveyJS - Open-Source JSON Form Builder to Create Dynamic Forms Right in Your App
  • InfluxDB - Power Real-Time Data Analytics at Scale
  • WorkOS - The modern identity platform for B2B SaaS
  • harden-runner

    Network egress filtering and runtime security for GitHub-hosted and self-hosted runners

  • Few hours back several malicious packages were released on npm registry. This video shows how some of these packages are making outbound calls as part of the preinstall step when executed in a GitHub Actions workflow. DNS Exfiltration and network calls detected by Harden-Runner GitHub Action https://github.com/step-security/harden-runner

  • supply-chain-goat

    Discontinued Hands-on tutorials to learn about software supply chain security (by varunsh-coder)

  • This is one of the GitHub Actions workflow runs: https://github.com/varunsh-coder/supply-chain-goat/actions/runs/2037070162

  • SurveyJS

    Open-Source JSON Form Builder to Create Dynamic Forms Right in Your App. With SurveyJS form UI libraries, you can build and style forms in a fully-integrated drag & drop form builder, render them in your JS app, and store form submission data in any backend, inc. PHP, ASP.NET Core, and Node.js.

    SurveyJS logo
NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts