DEV Community

Hauke T.
Hauke T.

Posted on

David Gilbertson Warned us About The Latest NPM Attack

In the light of the latest Supply-Chain Attack on npm, which (among others) hit chalk, I can't help but smile a little, because of the irony.
David Gilbertson imagined an attack like this 7 years ago: I’m harvesting credit card numbers and passwords from your site. Here’s how..
It's a nice read and it aged better than we would have hoped.

In his article he wrote the malicious Package himself:

People love pretty colours — it’s what separates us from dogs — so I wrote a package that lets you log to the console in any colour.

It's basically what chalk does - isn't it?

Top comments (0)