• realharo@lemm.ee
    link
    fedilink
    arrow-up
    13
    arrow-down
    1
    ·
    edit-2
    1 year ago

    Clickbait title.

    The packages were collectively downloaded 963 times before they were removed. The rogue packages include names like “noblox.js-vps,” “noblox.js-ssh,” and “noblox.js-secure,” and they were distributed across specific version ranges

    Is there any indication that anyone actually installed these, other than some bots that auto download all packages and such?

    You would have to really go out of your way to get infected by stuff like this.

    That being said, there are things npm could do to try to auto-detect “risky” packages (new, similar name to existing projects, few downloads, etc.) and require an additional layer of confirmation, or something like that.

    • atheken@programming.dev
      link
      fedilink
      arrow-up
      8
      arrow-down
      1
      ·
      1 year ago

      Also, as far as I can tell, they’re talking about devs that are building on the Roblox platform, not devs that are building the platform.

      In other words, random devs of varying skill levels getting name-squatted.

      It’s not good, but including Roblox in the title is definitely misleading/clickbait.

      • JackbyDev@programming.dev
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        1
        ·
        1 year ago

        It is a library to work with Roblox, saying Roblox isn’t misleading. I can agree that “Roblox devs” is misleading though.

        • atheken@programming.dev
          link
          fedilink
          arrow-up
          1
          arrow-down
          1
          ·
          edit-2
          1 year ago

          It’s misleading because it’s irrelevant and makes it sound like a platform breach.

          Try replacing Roblox with “Foozsplatz” and the implication of severity is completely different, even though the nature of what is being reported is unchanged.

          • JackbyDev@programming.dev
            link
            fedilink
            English
            arrow-up
            2
            arrow-down
            1
            ·
            1 year ago

            I’m confused, in this hypothetical is Foozsplatz a non sense word or is it meant to be a game like Roblox? If you mean the first, then yeah, obviously replacing a proper noun with gibberish changes the implication. If you mean the second then no, it would have the same implication.

            • atheken@programming.dev
              link
              fedilink
              arrow-up
              1
              arrow-down
              2
              ·
              edit-2
              1 year ago

              It literally doesn’t matter. You can remove the word and the nature of the problem being discussed is still the same. What platform is being targeted has nothing to do with the example problem. Roblox is only mentioned to sensationalize it and get clicks.

                • atheken@programming.dev
                  link
                  fedilink
                  arrow-up
                  1
                  arrow-down
                  1
                  ·
                  edit-2
                  1 year ago

                  The thread you are in and my response made it clear that the headline is clickbait by including that irrelevant detail.

                  If they didn’t include that word in the post title, it would have no traction at all.

                  • JackbyDev@programming.dev
                    link
                    fedilink
                    English
                    arrow-up
                    2
                    ·
                    1 year ago

                    “Roblox library is target of typo squatting” is a perfectly accurate headline that uses the word Roblox and is not clickbait.