Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fsevents <= 1.2.10 , is not malicious anymore #527

Open
mustafanaa opened this issue Jun 9, 2024 · 1 comment
Open

fsevents <= 1.2.10 , is not malicious anymore #527

mustafanaa opened this issue Jun 9, 2024 · 1 comment

Comments

@mustafanaa
Copy link

It was confirmed that AWS had agreed to take ownership and block all access to the S3 bucket and as such it has mitigated the straightforward attack vector - this can be further confirmed by attempting to access the bucket which returns a AllAccessDisabled or NoSuchBucket error , therefor I do not think that this packages are malicious anymore.

@calebbrown
Copy link
Contributor

Hi mustafanaa,

Thank you for posting that context. It is nice to know that AWS has done more to block this attack vector from occurring again too.

However, despite this, I do not think the package versions should be marked as not malicious anymore.

  1. anyone who installed the affected versions while the compromised binaries where available should know that they were very likely compromised
  2. at some future date AWS may change their behavior and allow the package to be compromised again

I hope that helps.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants