Changelog Interviews

The insider perspective on the event-stream compromise


Listen Later

Adam and Jerod talk with Dominic Tarr, creator of event-stream, the IO library that made recent news as the latest malicious package in the npm registry. event-stream was turned malware, designed to target a very specific development environment and harvest account details and private keys from Bitcoin accounts.

They talk through Dominic’s backstory as a prolific contributor to open source, his stance on this package, his work in open source, the sequence of events around the hack, how we can and should handle maintainer-ship of open source infrastructure over the full life-cycle of the code’s usefulness, and what some best practices are for moving forward from this kind of attack.

Join the discussion

Changelog++ members support our work, get closer to the metal, and make the ads disappear. Join today!

Sponsors:

  • RollbarWe catch our errors before our users do because of Rollbar. Resolve errors in minutes, and deploy your code with confidence. Learn more at rollbar.com/changelog.
  • LinodeOur cloud server of choice. Deploy a fast, efficient, native SSD cloud server for only $5/month. Get 4 months free using the code changelog2018. Start your server - head to linode.com/changelog
  • GoCD – GoCD is an on-premise open source continuous delivery server created by ThoughtWorks that lets you automate and streamline your build-test-release cycle for reliable, continuous delivery of your product.
  • Command Line Heroes – A new podcast about the epic true tales of the developers, hackers, and open source rebels revolutionizing the tech landscape from the command line up. Presented by Red Hat.
  • Featuring:

    • Dominic Tarr – Website, GitHub, X
    • Adam Stacoviak – Website, GitHub, LinkedIn, Mastodon, X
    • Jerod Santo – GitHub, LinkedIn, Mastodon, X

    Show Notes:

    • The issue that kicked off everything
    • We covered the incident on Changelog News
    • Here’s Dominic’s statement that we reference repeatedly
    • Felix Krause had some on-point commentary on Twitter
    • TideLift says event-stream gets 2 million downloads per week
    • SwiftOnSecurity also chimed in on Twitter
    • Learn more about Project Xanadu
    • We discussed Reproducible Builds with Chris Lamb back in the day
    • Also check out A call for kindness in open source with Brett Cannon
    • Something missing or broken? PRs welcome!

      ...more
      View all episodesView all episodes
      Download on the App Store

      Changelog InterviewsBy Changelog Media

      • 5
      • 5
      • 5
      • 5
      • 5

      5

      5 ratings


      More shows like Changelog Interviews

      View all
      The Changelog: Software Development, Open Source by Changelog Media

      The Changelog: Software Development, Open Source

      289 Listeners

      Making Sense with Sam Harris by Sam Harris

      Making Sense with Sam Harris

      26,319 Listeners

      Software Engineering Daily by Software Engineering Daily

      Software Engineering Daily

      622 Listeners

      Syntax - Tasty Web Development Treats by Wes Bos & Scott Tolinski - Full Stack JavaScript Web Developers

      Syntax - Tasty Web Development Treats

      987 Listeners

      REWORK by 37signals

      REWORK

      210 Listeners

      The Diary Of A CEO with Steven Bartlett by DOAC

      The Diary Of A CEO with Steven Bartlett

      8,459 Listeners

      Practical AI by Practical AI LLC

      Practical AI

      207 Listeners

      Sicherheitshalber by Der Podcast zur sicherheitspolitischen Lage in Deutschland, Europa und der Welt.

      Sicherheitshalber

      47 Listeners

      All-In with Chamath, Jason, Sacks & Friedberg by All-In Podcast, LLC

      All-In with Chamath, Jason, Sacks & Friedberg

      9,938 Listeners

      Dwarkesh Podcast by Dwarkesh Patel

      Dwarkesh Podcast

      517 Listeners

      Huberman Lab by Scicomm Media

      Huberman Lab

      29,185 Listeners

      Plain English with Derek Thompson by The Ringer

      Plain English with Derek Thompson

      2,230 Listeners

      Oxide and Friends by Oxide Computer Company

      Oxide and Friends

      62 Listeners

      Changelog News by Changelog Media

      Changelog News

      14 Listeners

      Rust in Production by Matthias Endler

      Rust in Production

      26 Listeners