Skip to content

Commit 3582a84

Browse files
authored
docs: update vuln reporter to be more accurate (#915)
1 parent 4acd8d3 commit 3582a84

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

src/blog/npm-supply-chain-compromise-postmortem.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -68,7 +68,7 @@ All times UTC. Local timestamps from GitHub API and npm registry.
6868

6969
| Time | Event |
7070
| ----------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
71-
| 2026-05-11 ~19:50 | External researcher (`carlini`) opens issue #7383 with a complete writeup of the malicious `optionalDependencies` fingerprint and the package list (initially 14 of the 42) |
71+
| 2026-05-11 ~19:50 | External researcher `ashishkurmi` working for StepSecurity opens issue #7383 with a complete writeup of the malicious `optionalDependencies` fingerprint and the package list (initially 14 of the 42) |
7272
| 2026-05-11 ~19:50 | Researcher notifies npm security directly |
7373
| 2026-05-11 ~20:00 | Manuel acknowledges in #7383 — incident response begins |
7474
| 2026-05-11 ~20:10 | Manuel removes all other team push permissions on GitHub in case of user machines have been compromised |
@@ -139,7 +139,7 @@ The chain only works because each vulnerability bridges the trust boundary the o
139139

140140
### How we found out
141141

142-
Detection was external. `carlini` opened issue #7383 ~20 minutes after the publish, with full technical analysis. Tanner received a phone call from Socket.dev just moments after starting the war room confirming the situation.
142+
Detection was external. External researcher `ashishkurmi` working for StepSecurity opened issue #7383 ~20 minutes after the publish, with full technical analysis. Tanner received a phone call from Socket.dev just moments after starting the war room confirming the situation.
143143

144144
### IOC fingerprints (for downstream maintainers and security tools)
145145

0 commit comments

Comments
 (0)