Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Just absolutely no regard for security at all.

Just absolutely no regard for security at all.

Scheduled Pinned Locked Moved Uncategorized
13 Posts 10 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • mhoye@cosocial.caM mhoye@cosocial.ca

    Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in a system that was foundationally built on trust and trustworthiness.

    lerxst@az.socialL This user is from outside of this forum
    lerxst@az.socialL This user is from outside of this forum
    lerxst@az.social
    wrote last edited by
    #3

    @mhoye If we didn't learn from the left pad incident, we never will. This is just a new payload for an existing threat vector.

    1 Reply Last reply
    0
    • mhoye@cosocial.caM mhoye@cosocial.ca

      Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in a system that was foundationally built on trust and trustworthiness.

      pmc@mastodon.ffcentral.netP This user is from outside of this forum
      pmc@mastodon.ffcentral.netP This user is from outside of this forum
      pmc@mastodon.ffcentral.net
      wrote last edited by
      #4

      @mhoye @cwebber Why the hell does a triage bot have the NPM token in the first place

      1 Reply Last reply
      0
      • mhoye@cosocial.caM mhoye@cosocial.ca

        Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in a system that was foundationally built on trust and trustworthiness.

        delta_vee@mstdn.caD This user is from outside of this forum
        delta_vee@mstdn.caD This user is from outside of this forum
        delta_vee@mstdn.ca
        wrote last edited by
        #5

        @mhoye This is the real "we're cooked"

        1 Reply Last reply
        0
        • mhoye@cosocial.caM mhoye@cosocial.ca

          Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in a system that was foundationally built on trust and trustworthiness.

          hennell@phpc.socialH This user is from outside of this forum
          hennell@phpc.socialH This user is from outside of this forum
          hennell@phpc.social
          wrote last edited by
          #6

          @mhoye While the whole situation from AI injection down to 'packages can postinstall global packages' is a series of bad to insane decisions, the only thing I really don't understand is ... why install openclaw on machines? Was this trying to achieve something or just show it was possible?

          1 Reply Last reply
          0
          • mhoye@cosocial.caM mhoye@cosocial.ca

            Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in a system that was foundationally built on trust and trustworthiness.

            endorama@hachyderm.ioE This user is from outside of this forum
            endorama@hachyderm.ioE This user is from outside of this forum
            endorama@hachyderm.io
            wrote last edited by
            #7

            @mhoye could you share the source? Thanks in advance

            mhoye@cosocial.caM 1 Reply Last reply
            0
            • mhoye@cosocial.caM mhoye@cosocial.ca

              Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in a system that was foundationally built on trust and trustworthiness.

              stepheneb@ruby.socialS This user is from outside of this forum
              stepheneb@ruby.socialS This user is from outside of this forum
              stepheneb@ruby.social
              wrote last edited by
              #8

              @mhoye

              “the CLI binary (dist/cli.mjs) and all other package contents are identical to the legitimate cline@2.2.3 release.
              A corrected version (2.4.0) was published at 11:23 AM PT and 2.3.0 was deprecated at 11:30 AM PT. The compromised token has been revoked and npm publishing now uses OIDC provenance via GitHub Actions.”

              Link Preview Image
              Unauthorized npm publish of Cline CLI cline@2.3.0 with modified postinstall script to install openclaw

              GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects.

              favicon

              GitHub (github.com)

              stepheneb@ruby.socialS 1 Reply Last reply
              0
              • stepheneb@ruby.socialS stepheneb@ruby.social

                @mhoye

                “the CLI binary (dist/cli.mjs) and all other package contents are identical to the legitimate cline@2.2.3 release.
                A corrected version (2.4.0) was published at 11:23 AM PT and 2.3.0 was deprecated at 11:30 AM PT. The compromised token has been revoked and npm publishing now uses OIDC provenance via GitHub Actions.”

                Link Preview Image
                Unauthorized npm publish of Cline CLI cline@2.3.0 with modified postinstall script to install openclaw

                GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects.

                favicon

                GitHub (github.com)

                stepheneb@ruby.socialS This user is from outside of this forum
                stepheneb@ruby.socialS This user is from outside of this forum
                stepheneb@ruby.social
                wrote last edited by
                #9

                @mhoye

                I didn’t know about using “OpenID Connect (OIDC) to authenticate GitHub Actions” and wonder how many surfaces it closes and whether it opens new surfaces?

                Link Preview Image
                OpenID Connect reference - GitHub Docs

                Find information about using OpenID Connect (OIDC) to authenticate GitHub Actions workflows with cloud providers.

                favicon

                GitHub Docs (docs.github.com)

                1 Reply Last reply
                0
                • mhoye@cosocial.caM mhoye@cosocial.ca

                  Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in a system that was foundationally built on trust and trustworthiness.

                  mhoye@cosocial.caM This user is from outside of this forum
                  mhoye@cosocial.caM This user is from outside of this forum
                  mhoye@cosocial.ca
                  wrote last edited by
                  #10

                  Links:

                  Link Preview Image
                  A GitHub Issue Title Compromised 4,000 Developer Machines

                  A prompt injection in a GitHub issue triggered a chain reaction that ended with 4,000 developers getting OpenClaw installed without consent. The attack composes well-understood vulnerabilities into something new: one AI tool bootstrapping another.

                  favicon

                  (grith.ai)

                  Link Preview Image
                  Unauthorized npm publish of Cline CLI cline@2.3.0 with modified postinstall script to install openclaw

                  GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects.

                  favicon

                  GitHub (github.com)

                  1 Reply Last reply
                  0
                  • endorama@hachyderm.ioE endorama@hachyderm.io

                    @mhoye could you share the source? Thanks in advance

                    mhoye@cosocial.caM This user is from outside of this forum
                    mhoye@cosocial.caM This user is from outside of this forum
                    mhoye@cosocial.ca
                    wrote last edited by
                    #11

                    @endorama

                    Link Preview Image
                    A GitHub Issue Title Compromised 4,000 Developer Machines

                    A prompt injection in a GitHub issue triggered a chain reaction that ended with 4,000 developers getting OpenClaw installed without consent. The attack composes well-understood vulnerabilities into something new: one AI tool bootstrapping another.

                    favicon

                    (grith.ai)

                    1 Reply Last reply
                    0
                    • mhoye@cosocial.caM mhoye@cosocial.ca

                      Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in a system that was foundationally built on trust and trustworthiness.

                      cdamian@rls.socialC This user is from outside of this forum
                      cdamian@rls.socialC This user is from outside of this forum
                      cdamian@rls.social
                      wrote last edited by
                      #12

                      @mhoye
                      Could you provide a source URL to this?

                      1 Reply Last reply
                      0
                      • mhoye@cosocial.caM mhoye@cosocial.ca

                        Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in a system that was foundationally built on trust and trustworthiness.

                        pseudonym@mastodon.onlineP This user is from outside of this forum
                        pseudonym@mastodon.onlineP This user is from outside of this forum
                        pseudonym@mastodon.online
                        wrote last edited by
                        #13

                        @mhoye

                        #infosec

                        Install attack surface as a service.

                        IASaaS

                        No, swap that...

                        Attack Interface Surface as a Service

                        AISaaS

                        1 Reply Last reply
                        0
                        • R relay@relay.an.exchange shared this topic
                        Reply
                        • Reply as topic
                        Log in to reply
                        • Oldest to Newest
                        • Newest to Oldest
                        • Most Votes


                        • Login

                        • Login or register to search.
                        • First post
                          Last post
                        0
                        • Categories
                        • Recent
                        • Tags
                        • Popular
                        • World
                        • Users
                        • Groups