Wait, binding.gyp Can Do What? Exploring npm's Weirdest Build System
aikido.dev | blog | #cloud | #supply-chain | #malware | #npm | #supply-chain-attack | #supply-chain-security | #node-gyp | #binding-gyp | #miasma | #build-systems | #arbitrary-code-execution | #supply-chain-attacks | #build-system
Summary
Following the Miasma worm that hit 32 official Red Hat npm packages, this deep dive shows how binding.gyp—npm's least-scrutinized build file—enables arbitrary code execution via node-gyp rebuild.
- Published
- Collected
Skip to content