Comment on SSH keys stolen by stream of malicious PyPI and npm packages

ShaunaTheDead@kbin.social ⁨11⁩ ⁨months⁩ ago

This feels like a great application of AI to root around through the code of packages in these repos and find ones that access the ssh key directory at all to be looked at more thoroughly by a human.

source
Sort:hotnewtop