Readit News logoReadit News
zachleat commented on NPM debug and chalk packages compromised   aikido.dev/blog/npm-debug... · Posted by u/universesquid
junon · 5 days ago
Hi, yep I got pwned. Sorry everyone, very embarrassing.

More info:

- https://github.com/chalk/chalk/issues/656

- https://github.com/debug-js/debug/issues/1005#issuecomment-3...

Affected packages (at least the ones I know of):

- ansi-styles@6.2.2

- debug@4.4.2 (appears to have been yanked as of 8 Sep 18:09 CEST)

- chalk@5.6.1

- supports-color@10.2.1

- strip-ansi@7.1.1

- ansi-regex@6.2.1

- wrap-ansi@9.0.1

- color-convert@3.1.1

- color-name@2.0.1

- is-arrayish@0.3.3

- slice-ansi@7.1.1

- color@5.0.1

- color-string@2.1.1

- simple-swizzle@0.2.3

- supports-hyperlinks@4.1.1

- has-ansi@6.0.1

- chalk-template@1.1.1

- backslash@0.2.1

It looks and feels a bit like a targeted attack.

Will try to keep this comment updated as long as I can before the edit expires.

---

Chalk has been published over. The others remain compromised (8 Sep 17:50 CEST).

NPM has yet to get back to me. My NPM account is entirely unreachable; forgot password system does not work. I have no recourse right now but to wait.

Email came from support at npmjs dot help.

Looked legitimate at first glance. Not making excuses, just had a long week and a panicky morning and was just trying to knock something off my list of to-dos. Made the mistake of clicking the link instead of going directly to the site like I normally would (since I was mobile).

Just NPM is affected. Updates to be posted to the `/debug-js` link above.

Again, I'm so sorry.

zachleat · 5 days ago
Yo, someone at npm needs to unpublish simple-swizzle@0.2.3 IMMEDIATELY. It’s still actively compromised.
zachleat commented on A Front End Engineer's Manifesto   f2em.com/... · Posted by u/hdragomir
zachleat · 13 years ago
Please read the associated blog post that went along with the site. http://www.zachleat.com/web/manifesto/

"I’ve been reluctant to share the slides because I certainly don’t want developers to take them as dogmatic truth. Rather, I’d love for people to see a forest using trees they’ve planted themselves."

Certainly scrolling could be improved. I'll definitely look into improving the performance. I honestly had no idea this slide deck would get this much attention.

zachleat commented on Farewell Stack Exchange   codinghorror.com/blog/201... · Posted by u/dko
benmathes · 14 years ago
Have you heard of an ultrarun before? It's a run that's longer than a marathon, maybe 50 miles, maybe 100 miles. It's all dependent on the local geography.

You don't run those at a fast pace, you complete them in like 8-11 hours. Perhaps that's a better metaphor.

zachleat · 14 years ago
Does this make it safe to assume that neither of the commenters here run marathons?
zachleat commented on I swapped my MacBook for an iPad+Linode   yieldthought.com/post/122... · Posted by u/moconnor
raganwald · 14 years ago
There are two kinds of programmers: Those who’ve earned their experience the hard way, and insufferable know-it-alls who parrot whatever was in the last witty blog post they read.

There’s zero shame in being the first kind :-)

zachleat · 14 years ago
What's the URL to the blog post where you read this? :)

u/zachleat

KarmaCake day47March 3, 2010View Original