event-stream: Analysis of a Compromised npm Package episode artwork

EPISODE · Nov 27, 2018 · 21 MIN

event-stream: Analysis of a Compromised npm Package

from The OWASP Podcast Series · host The OWASP Podcast Series

Once again, the pattern of taking over a known package and modifying it with malicious intent has happened. In this case, it's with the event-stream module in the npm repository. In this broadcast I speaker with Thomas Hunter, Software Developer at Intrinsic and author of "Compromised npm Package: event-stream", and Brian Fox, CTO of Sonatype, author of the Forbes "Open Source Developers And Infrastructure Are The New Front Line Of Security?" article. Compromised npm Package: event-stream https://medium.com/intrinsic/compromi... Open Source Developers And Infrastructure Are The New Front Line Of Security https://www.forbes.com/sites/forbestechcouncil/2018/05/11/open-source-developers-and-infrastructure-are-the-new-front-line-of-security/#2ad9e84457c2 Open Source Software Is Under Attack; New Event-Stream Hack Is Latest Proof https://blog.sonatype.com/open-source-software-is-under-attack-new-event-stream-hack-is-latest-proof

Episode metadata supplied by the publisher feed · Published Nov 27, 2018

Embed this episode

NOW PLAYING

event-stream: Analysis of a Compromised npm Package

0:00 21:36

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The OWASP Podcast Series?

This episode is 21 minutes long.

When was this The OWASP Podcast Series episode published?

This episode was published on November 27, 2018.

Can I download this The OWASP Podcast Series episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!