Microsoft has identified a npm supply chain compromise impacting 90+ redhat-cloud-services/* packages, including patch-client 4.0.4, insights-client 4.0.4, rbac-client 9.0.3, host-inventory-client 5.0.3, frontend-components 7.7.2, and others. The payload is a self-propagating worm that infects other npm packages and self-publishes.
Each compromised package adds a malicious preinstall hook, embedding an index.js script in the package.json that silently executes “node index.js” during installation, downloads Bun, and runs a payload that steals secrets from npm, GitHub, Amazon Web Services (AWS), and Secure Shell (SSH). The added code bloats index.js from ~8KB to ~4.3MB, acting as a heavily obfuscated ROT-9 eval loader.
If any of the compromised packages are installed, users and organizations should assume compromise, rotate credentials, revert to a previously trusted version, and block compromised packages. Identified compromised npm packages have been taken down, and we continue to work with the npm team. Microsoft continues to investigate this attack and will publish updates as more information is available.
@waozixyz If you go in here in that link you can read that you can still download apps from unverified developers but it will take extra steps to ensure the user understands the risks they are taking. You will, at the minimum, be locked out of the unverified apps for one day.
@sullens_dwagon@KRR1751 It was meant to be used in earlier versions of Windows. Obviously not to run a whole shell or regular programs but when older services would display messages that's where they would go, UI0Detect let the user switch to the Session 0 and view them there
@PraxLemon@KilKidd@blacknredtext This doesn't mean every single driver for every single WiFi card out there is included... One of the WiFi cards in my PC doesn't have drivers built into the kernel either
@yadavji_codes 1. Internal AOSP file manager, mainly used for choosing a file in some apps (usually you aren't even supposed to see the icon)
2. Google Files app, used in Pixel phones but can be installed on any device