logoalt Hacker News

jeromegvlast Thursday at 11:10 PM1 replyview on HN

But it's not always massive, it's a good practice to see what the diff is and ensure there is no weird dependency (aka supply chain attack) showing up in there.


Replies

po1ntyesterday at 7:01 AM

In my opinion you have no chance of identifying supply chain attack like this. It's not like you will see "evil-package": "*" in there. Supply chain attacks happen by appending obfuscated code deep into dependency no one knew you had in the first place.