• just_another_person@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    1 year ago

    This isn’t really a supply chain attack. It’s more social engineering: fake users, forks, and non-verified code. They’re taking advantage of the fact that most people don’t use verified releases or packages code from open source projects.

    GitHub is not compromised, nor sending unintended payloads.

    • ikidd@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 year ago

      Many of the projects are backend dev tools, like the Atlas provider linked in the thread.