This is about NestJS, not NextJS.
HN user
everybackdoor
You can also fire events on pretty much any object, essentially creating a channel where the message bus queue is the vm event queue.
In 2024 we have linters and other static analysis tools for catching these kinds of things right in the IDE.
And a backdoor in a build tree
- They’re saying ”the community wants less boilerplate”
- They introduce what is effectively a black-box system
- The new system is expected to handle all application state
- They try to push it for frontend folks while also remarking that it would be useful for build systems
This has the same red flags the xz saga had.
Have we learnt nothing.
Lots of ”users” here vouching for the pattern and hoping it gets adopted. I bet this gets some nice damage control replies because there’s social engineering going on here right now and most seem to not be aware of it.
Look at the newest commits, do you see anything suspicious:
https://git.alpinelinux.org/aports/log/main/gettext
libunistring could also be affected as that has also been pushed there
JiaT75 was also a prolific contributor to xz over the past few years, so your assumptions are generally invalid at this point.
Funny you should say that, given they definitely have exploit code in `vcpkg`
They may be right: https://git.alpinelinux.org/aports/log/main/gettext
Timeline matches and there is a sudden switch of maintainer. And they add dependency to xz!