Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[SECURITY] coa is compromised #5872

Closed
Josh-Cena opened this issue Nov 4, 2021 · 4 comments
Closed

[SECURITY] coa is compromised #5872

Josh-Cena opened this issue Nov 4, 2021 · 4 comments
Labels
bug An error in the Docusaurus core causing instability or issues with its execution

Comments

@Josh-Cena
Copy link
Collaborator

Josh-Cena commented Nov 4, 2021

The coa package is compromised. Do NOT run install on your computer before there's a fix. The CI checks on our repo are failing because of this.

See the diff: https://my.diffend.io/npm/coa/2.0.2/2.0.4

And the issue: veged/coa#99

@Josh-Cena Josh-Cena added meta Meta-issue about the project itself. Either project maintenance or a list of other issues. bug An error in the Docusaurus core causing instability or issues with its execution and removed meta Meta-issue about the project itself. Either project maintenance or a list of other issues. labels Nov 4, 2021
@Josh-Cena
Copy link
Collaborator Author

The problematic versions are taken down. Quick action from NPM 👍

@slorber
Copy link
Collaborator

slorber commented Nov 4, 2021

😓 is this going to happen evrey week now

@Josh-Cena
Copy link
Collaborator Author

😓 is this going to happen evrey week now

Until NPM requires 2FA for popular packages :D

FYI the two hacks are initiated by the exact same person

@josh-kaplan
Copy link

It does look like this one only impacted Windows users (veged/coa#99)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug An error in the Docusaurus core causing instability or issues with its execution
Projects
None yet
Development

No branches or pull requests

3 participants