None
EN
Open Source Malware with Brian Fox
['Josh Bressers']
Open Source Security
I recently sat down with Brian Fox, CTO and co-founder of Sonatype, about a report they recently published about malware in open source ecosystems. NPM packages can execute scripts on install which is basically remote code execution, and NPM love to upgrade packages aggressively by default. It’s not always possible to know what “normal” open source development looks like, but we can know what abnormal open source development looks like.