Node Modules Hijacking

Not new exactly, but an important conversation.

If you consider DLL hijacking to be a concern, so is this—except worse in some ways because I guarantee your EDR isn’t watching JavaScript applications like it watches DLLs.

My favorite sentence is

They do not treat CWE-427 (Uncontrolled Search Path Element) as a vulnerability, pushing responsibility onto application developers.

Because I’ve had so many arguments with vendors about CWE-*** and they are just like “fEaTuRe nOt A bUg!”