Researcher hacks Microsoft, Apple, more in novel supply chain attack

Discussion in 'other security issues & news' started by Minimalist, Feb 9, 2021.

  1. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,909
    Location:
    Slovenia, EU
    https://www.bleepingcomputer.com/ne...soft-apple-more-in-novel-supply-chain-attack/
     
  2. Floyd 57

    Floyd 57 Registered Member

    Joined:
    Mar 17, 2017
    Posts:
    1,296
    Location:
    Europe
    Birsan soon realized, should a dependency package used by an application exist in both a public open-source repository and your private build, the public package would get priority and be pulled instead -- without needing any action from the developer.

    In some cases, as with PyPI packages, the researcher noticed that the package with the higher version would be prioritized regardless of wherever it was located.

    There we go, ez fix


    But still, he reported to SO many companies and only 130K... He could have done anything
     
  3. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,909
    Location:
    Slovenia, EU
    I agree.
    Also strange that packages are identified by name and not some other (harder to spoof) identifier. It looks like supply chain attacks will be popular this year.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.