Skip to content

Chore: Untrusted Dev Machine (Node.js Sandbox)Β #179

Description

@nelsonic

Sadly, I no longer trust anything built with Node.js. πŸ™…β€β™‚οΈ (and neither should you...! 😬)
Not saying this from a "consumer" perspective, but rather as an engineer/developer. πŸ§‘β€πŸ’»
Running code written by random strangers has always been a matter of trust. 🀝🏻
Increasingly there are Supply Chain Attacks targeting dependencies of popular packages. 😈

e.g: https://www.cisa.gov/news-events/alerts/2025/09/23/widespread-supply-chain-compromise-impacting-npm-ecosystem πŸ›
Or Reddit if you prefer: https://www.reddit.com/r/node/comments/1rin5bm/supply_chain_attacks_via_npm_any_mitigation/ πŸ€”
Even the NHS is alerting about this: https://digital.nhs.uk/cyber-alerts/2026/cc-4781 πŸ‘©πŸ»β€βš•οΈ

This means malicious actors are succeeding at injecting evil code into dependencies ☠️
which then infect/hack the host machine (e.g: developer's laptop or server) πŸ’»
and steal credentials, crypto keys, etc. πŸ’°

Note: If you aren't yet paranoid about system security, πŸ”’
you either (naively) think you "don't have anything to lose"
or "it won't happen to me" ... until it does!
So learn to be proactive with your security.

It's Going To Get Much Worse! 😬

"AI agents uploaded malicious packages to RubyGems":
https://www.reuters.com/legal/litigation/openai-agents-attacked-software-service-rubygems-before-hugging-face-incident-2026-09-11/
What this means is:

  1. Ai labs are going to release proof-of-concept malicious code into public package management repositories to showcase what their models can do. Yes, even if it results in lawsuits, they will still do it and pretend it was unintentional.
  2. Malicious actors are going to use both Open and Closed models to do similar malicious code injection into packages. πŸ“¦
  3. GitHub accounts will be compromised by malicious code running on the Dev's machine and used to submit PRs that appear to come from legitimate people but are in fact malicious. πŸ’€
  4. The cycle will continue until everyone in the target ecosystem is infected or whatever malicious goal is achieved. πŸ΄β€β˜ οΈ

Todo

  • Revive Mac Mini M1 (recent Mac that is fully supported with latest macOS and security patches) ⏻
  • Setup on dedicated desk πŸ–₯️
  • Connect to DMZ internet (not @home network) πŸ›œ
  • Figure out how to isolate any node projects I run on the machine, e.g: sandbox with Docker? 🐳

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    T25mTime Estimate 25 Minuteschorea tedious but necessary task often paying technical debtdiscussShare your constructive thoughts on how to make progress with this issuehelp wantedIf you can help make progress with this issue, please comment!priority-1Highest priority issue. This is costing us money every minute that passes.tech-debtA feature/requirement implemented in a sub-optimal way & must be re-writtentechnicalA technical issue that requires understanding of the code, infrastructure or dependencies

    Type

    Projects

    • Status
      More ToDo ThanCanEver Be Done

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions