Security Assessment: Simplechat is SAFE from qix NPM Supply Chain Attack #414
Closed
Paul Lizer (paullizer)
started this conversation in
General
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
After thoroughly reviewing the simplechat codebase against the compromised packages from the NPM supply chain attack, I can confirm that we are not affected by this malware.
Anatomy of a Billion-Download NPM Supply-Chain Attack
Limited Node.js Surface Area:
node_modulesdirectoriesCI/CD Usage:
Risk Assessment: MINIMAL
All reactions