Self-propagating malware poisons open source software and wipes Iran-based machines
Development houses: It's time to check your networks for infections.
https://arstechnica.com/security/2026/03/self-propagating-malware-poisons-open-source-software-and-wipes-iran-based-machines/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social

@arstechnica

OK, *now* is it time to acknowledge that the npm model of dependency management is just stupid?

@cwbussard @arstechnica not necessarily the model, more the fact that you can arbitrary scripts as part of the installation.