Changelog Interviews

The insider perspective on the event-stream compromise


Listen Later

Adam and Jerod talk with Dominic Tarr, creator of event-stream, the IO library that made recent news as the latest malicious package in the npm registry. event-stream was turned malware, designed to target a very specific development environment and harvest account details and private keys from Bitcoin accounts.

They talk through Dominic’s backstory as a prolific contributor to open source, his stance on this package, his work in open source, the sequence of events around the hack, how we can and should handle maintainer-ship of open source infrastructure over the full life-cycle of the code’s usefulness, and what some best practices are for moving forward from this kind of attack.

Join the discussion

Changelog++ members support our work, get closer to the metal, and make the ads disappear. Join today!

Sponsors:

  • RollbarWe catch our errors before our users do because of Rollbar. Resolve errors in minutes, and deploy your code with confidence. Learn more at rollbar.com/changelog.
  • LinodeOur cloud server of choice. Deploy a fast, efficient, native SSD cloud server for only $5/month. Get 4 months free using the code changelog2018. Start your server - head to linode.com/changelog
  • GoCD – GoCD is an on-premise open source continuous delivery server created by ThoughtWorks that lets you automate and streamline your build-test-release cycle for reliable, continuous delivery of your product.
  • Command Line Heroes – A new podcast about the epic true tales of the developers, hackers, and open source rebels revolutionizing the tech landscape from the command line up. Presented by Red Hat.
  • Featuring:

    • Dominic Tarr – Website, GitHub, X
    • Adam Stacoviak – Website, GitHub, LinkedIn, Mastodon, X
    • Jerod Santo – GitHub, LinkedIn, Mastodon, X

    Show Notes:

    • The issue that kicked off everything
    • We covered the incident on Changelog News
    • Here’s Dominic’s statement that we reference repeatedly
    • Felix Krause had some on-point commentary on Twitter
    • TideLift says event-stream gets 2 million downloads per week
    • SwiftOnSecurity also chimed in on Twitter
    • Learn more about Project Xanadu
    • We discussed Reproducible Builds with Chris Lamb back in the day
    • Also check out A call for kindness in open source with Brett Cannon
    • Something missing or broken? PRs welcome!

      ...more
      View all episodesView all episodes
      Download on the App Store

      Changelog InterviewsBy Changelog Media

      • 5
      • 5
      • 5
      • 5
      • 5

      5

      5 ratings


      More shows like Changelog Interviews

      View all
      Planet Money by NPR

      Planet Money

      30,839 Listeners

      The Changelog: Software Development, Open Source by Changelog Media

      The Changelog: Software Development, Open Source

      284 Listeners

      Conversations with Tyler by Mercatus Center at George Mason University

      Conversations with Tyler

      2,395 Listeners

      Twenty Thousand Hertz by Dallas Taylor

      Twenty Thousand Hertz

      3,924 Listeners

      Python Bytes by Michael Kennedy and Brian Okken

      Python Bytes

      215 Listeners

      NVIDIA AI Podcast by NVIDIA

      NVIDIA AI Podcast

      331 Listeners

      Syntax - Tasty Web Development Treats by Wes Bos & Scott Tolinski - Full Stack JavaScript Web Developers

      Syntax - Tasty Web Development Treats

      987 Listeners

      Darknet Diaries by Jack Rhysider

      Darknet Diaries

      7,879 Listeners

      Sean Carroll's Mindscape: Science, Society, Philosophy, Culture, Arts, and Ideas by Sean Carroll | Wondery

      Sean Carroll's Mindscape: Science, Society, Philosophy, Culture, Arts, and Ideas

      4,142 Listeners

      Practical AI by Practical AI LLC

      Practical AI

      192 Listeners

      Dwarkesh Podcast by Dwarkesh Patel

      Dwarkesh Podcast

      417 Listeners

      Oxide and Friends by Oxide Computer Company

      Oxide and Friends

      47 Listeners

      The AI Daily Brief (Formerly The AI Breakdown): Artificial Intelligence News and Analysis by Nathaniel Whittemore

      The AI Daily Brief (Formerly The AI Breakdown): Artificial Intelligence News and Analysis

      485 Listeners

      Changelog News by Changelog Media

      Changelog News

      13 Listeners

      Changelog & Friends by Changelog Media

      Changelog & Friends

      2 Listeners