logoalt Hacker News

subarcticyesterday at 11:42 PM1 replyview on HN

Does it matter? The individual researchers could look at brand-new published packages just the same


Replies

hunter2_today at 2:45 AM

For researchers who notice new releases as soon as they are published and discover malice based on that alone, I agree, and every step of that can be automated to some level of effectiveness.

But for researchers who aren't sufficiently effective until the first victim starts shouting that something went sideways, the malicious actor would be wise to simply ensure no victim is aware until well after the cooldown period, implementing novel obfuscation that evades static analysis and the like.

show 1 reply