Back

Why Does an NPM Math Library Need an Encrypted Loader?

37 points1 hoursafedep.io
altairprime17 minutes ago

[delayed]

nextzck20 minutes ago

Fascinating how intricate the target selection is on this

j2kun33 minutes ago

Why in the world would that specific 3x3 matrix be a trigger for an attack? Are they trying to find someone doing some particular kind of numerical analysis?

zarzavat28 minutes ago

Presumably it's so it can be used as a subdependency for setting up an attack in a popular, legitimate package, e.g. via a pull request. The code in the legitimate package would not arouse suspicion at all.

fshafique21 minutes ago

Does the FBI or any other law-enforcement office follow up on these backdoors? Is this considered a crime, or even conspiracy to commit a crime, or is it only the act of using the backdoor that's a crime?

I can also see that it's still up in NPM without any warning of any kind: - https://www.npmjs.com/package/mathmain

But the Github repo for the package and the author are down: - https://github.com/allendev12 - https://github.com/allendev12/mathmain