Researchers Uncover npm Package Delivering RAT Via Microsoft Executable
expertmadman @ expertmadman @sh.itjust.works Posts 4Comments 5Joined 2 yr. ago
expertmadman @ expertmadman @sh.itjust.works
Posts
4
Comments
5
Joined
2 yr. ago
we’re working on a third party solution for this. Should have some updates that sandbox cargo builds shortly.
https://github.com/phylum-dev/birdcage
It’s a cross-platform sandbox that works on Linux via Landlock and macOS via Seatbelt. We’ve rolled this into our CLI (https://github.com/phylum-dev/cli) so you can do thinks like:
For example for npm, which currently uses the sandbox:
We’re adding this to cargo to similarly sandbox crate installations. Would love feedback and thoughts on our sandbox!