A lot of fingers in a lot pies
> The entire attack design assumes Linux or macOS execution environments, checking for os.platform() === 'linux' || 'darwin'. It deliberately skips Windows systems
If I were the conspiracy-minded sort I might jump to some wild conclusions here.
I mean it says something the developed the Linux Subsystem for Windows, but it’s an optional install.
So don’t expect PowerShell to be like a UNIX shell. It isn’t, and wasn’t meant to be one. It’s different, on purpose :)
I'm a die hard linux user, and some years ago took a windows gig on a whim. I find powershell fantastic and the only thing that makes my role bearable. Now, one of the first things i install on Linux is powershell.
MS doesn't care
Are you sure about this? Would love to see which ones.
The dev later said that Charlie notifying him probably shaved off some very important time for the remediation.
So in this case 2 different companies found it using automated tech before anyone else
There's no reason why Microsoft/npm can't do what we're doing, or any of the other handful to dozen companies that do similar things to us, to protect the supply chain.