Home / Companies / Snyk / Blog / Post Details
Content Deep Dive

A post-mortem of the malicious event-stream backdoor

Blog post from Snyk

Post Details
Company
Date Published
Author
Danny Grander, Liran Tal
Word Count
1,470
Company Posts That Month
4
Language
English
Hacker News Points
-
Post removed?
No
Summary

A malicious package, flatmap-stream, was published to npm and later added as a dependency to the widely used event-stream package by user right9ctrl. The event-stream package is a toolkit that provides utilities to creating and managing streams. Some time, and 8 million downloads later, applications all over the web were unwittingly running malicious code in production. This incident highlights the fragility of the open-source model if not respected and the need for responsible disclosure and security research as part of the development process.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.