RT by @a16z: Great piece from @a16z. A few things I’d add from the front lines of detecting the Axios attack: (opens in new tab)
<p>Great piece from <a href=" title="a16z">@a16z</a>. A few things I’d add from the front lines of detecting the Axios attack:<br> <br> Socket detecting the attack 16 minutes before publication is worth dwelling on. We caught plain-crypto-js because its behavior was anomalous the moment it appeared on npm – postinstall script, network access, OS fingerprinting, binary download, self-deletion. No CVE needed. The package told us what it was by what it did.<br> <br> The core issue is that AI age...
Read the original article