Probably something worth checking out on nodes on WMF clouds:
https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan#am-i-affected

Perhaps there is a way to check all automated deployments on TF and Gitlab? Not sure how many are there.

Fortunately I don't use axios that much myself so I'm not affected. Also I use `npm ci` for automated builds for a few years (which should use pre-tested package versions). So also might be worth checking if you use `npm i` in scripts.

And no, this is NOT an april fools. Google and Microsoft also wrote about this. The script has 3 separate paths for Linux, Mac and Windows.

Regards,
Nux
_______________________________________________
Cloud mailing list -- [email protected]
List information: 
https://lists.wikimedia.org/postorius/lists/cloud.lists.wikimedia.org/

Reply via email to