• magic_lobster_party@fedia.io
    link
    fedilink
    arrow-up
    47
    ·
    4 days ago

    it’s the kind of dependency developers install without a second thought

    I got a feeling this is an attack vector that will continue to grow, as now there’s vibe coding frameworks installing random dependencies without a thought at all.

    • corsicanguppy@lemmy.ca
      link
      fedilink
      English
      arrow-up
      12
      arrow-down
      1
      ·
      edit-2
      2 hours ago

      There’s two things at play, here:

      • installing dependencies without checking
      • a framework that will allow this

      Both are absolutely the fault of the user.

  • rollerbang@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    3 days ago

    I’ve got to research how can I do individual sandbox/jail for projects that are opened using VSC. Maybe dockerize everything 🤷‍♂️

  • iAmTheTot@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    1
    ·
    4 days ago

    For a layman, how might one deduce if they were affected? I cannot really tell from the article if this was particularly widespread.

    • Deestan@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      4 days ago

      No way to know for sure based on this. If you used any app that “works with” WhatsApp in any way, you could be affected.