Upwind First to Detect One of the Most Deceptive npm Compromises Yet Recorded
Most security incidents map onto an existing budget line. This one does not.
The compromise Upwind Security was first to report did not exploit a vulnerability, defeat a control, or breach a perimeter. It arrived through a supported feature of the package manager, executing exactly as designed, inside build systems most security organizations do not formally own.
The Asset Nobody Signed Off On
Ask a security team to enumerate third-party risk and the answer describes vendors. Contracts, questionnaires, assessments, renewals. Procurement gates the relationship and someone signs.
The dependency tree bypasses all of it. A developer adds one package, that package pulls forty more, and a build resolves several hundred transitively. No contract exists. No assessment happened. No one signed anything.
keyv illustrates the gap at scale, drawing approximately 154 million weekly downloads. The overwhelming majority of projects consuming it never chose it. It arrived underneath something else.
Upwind's Combined...
Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE