Probably something worth checking out on nodes on WMF clouds:
https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan#am-i-affected
Perhaps there is a way to check all automated deployments on TF and
Gitlab? Not sure how many are there.
Fortunately I don't use axios that much myself so I'm not affected. Also
I use `npm ci` for automated builds for a few years (which should use
pre-tested package versions). So also might be worth checking if you use
`npm i` in scripts.
And no, this is NOT an april fools. Google and Microsoft also wrote
about this. The script has 3 separate paths for Linux, Mac and Windows.
Regards,
Nux
_______________________________________________
Cloud mailing list -- [email protected]
List information:
https://lists.wikimedia.org/postorius/lists/cloud.lists.wikimedia.org/