-
Notifications
You must be signed in to change notification settings - Fork 25
Chore: Untrusted Dev Machine (Node.js Sandbox)Β #179
Copy link
Copy link
Open
Labels
T25mTime Estimate 25 MinutesTime Estimate 25 Minuteschorea tedious but necessary task often paying technical debta tedious but necessary task often paying technical debtdiscussShare your constructive thoughts on how to make progress with this issueShare your constructive thoughts on how to make progress with this issuehelp wantedIf you can help make progress with this issue, please comment!If you can help make progress with this issue, please comment!priority-1Highest priority issue. This is costing us money every minute that passes.Highest priority issue. This is costing us money every minute that passes.tech-debtA feature/requirement implemented in a sub-optimal way & must be re-writtenA feature/requirement implemented in a sub-optimal way & must be re-writtentechnicalA technical issue that requires understanding of the code, infrastructure or dependenciesA technical issue that requires understanding of the code, infrastructure or dependencies
Description
Activity
Metadata
Metadata
Assignees
Labels
T25mTime Estimate 25 MinutesTime Estimate 25 Minuteschorea tedious but necessary task often paying technical debta tedious but necessary task often paying technical debtdiscussShare your constructive thoughts on how to make progress with this issueShare your constructive thoughts on how to make progress with this issuehelp wantedIf you can help make progress with this issue, please comment!If you can help make progress with this issue, please comment!priority-1Highest priority issue. This is costing us money every minute that passes.Highest priority issue. This is costing us money every minute that passes.tech-debtA feature/requirement implemented in a sub-optimal way & must be re-writtenA feature/requirement implemented in a sub-optimal way & must be re-writtentechnicalA technical issue that requires understanding of the code, infrastructure or dependenciesA technical issue that requires understanding of the code, infrastructure or dependencies
Type
Projects
- StatusShow more project fieldsMore ToDo ThanCanEver Be Done
Sadly, I no longer trust anything built with
Node.js. π ββοΈ (and neither should you...! π¬)Not saying this from a "consumer" perspective, but rather as an engineer/developer. π§βπ»
Running code written by random strangers has always been a matter of trust. π€π»
Increasingly there are Supply Chain Attacks targeting dependencies of popular packages. π
This means malicious actors are succeeding at injecting evil code into dependencies β οΈ
which then infect/hack the host machine (e.g: developer's laptop or server) π»
and steal credentials, crypto keys, etc. π°
It's Going To Get Much Worse! π¬
"AI agents uploaded malicious packages to
RubyGems":https://www.reuters.com/legal/litigation/openai-agents-attacked-software-service-rubygems-before-hugging-face-incident-2026-09-11/
What this means is:
Ailabs are going to release proof-of-concept malicious code into public package management repositories to showcase what their models can do. Yes, even if it results in lawsuits, they will still do it and pretend it was unintentional.GitHubaccounts will be compromised by malicious code running on the Dev's machine and used to submit PRs that appear to come from legitimate people but are in fact malicious. πcontinueuntil everyone in the target ecosystem is infected or whatever malicious goal is achieved. π΄ββ οΈTodo
Mac Mini M1(recent Mac that is fully supported with latestmacOSand security patches) β»@homenetwork) πDocker? π³