Hacker News new | past | comments | ask | show | jobs | submit login
Show HN: Test Your Defenses with a Malware-Simulator Package (github.com/step-security)
2 points by varunsharma07 on March 22, 2022 | hide | past | favorite | 1 comment



A new tutorial has been added to https://github.com/step-security/supply-chain-goat/blob/main... to perform behavior analysis of dependencies.

For this a package was needed to simulate behavior of past hijacked packages. https://www.npmjs.com/package/@step-security/malware-simulat... makes an outbound call in a preinstall step.

You can think of the @step-security/malware-simulator package being like the EICAR file, which is used as a test file for anti-virus software.

Can be used to test if you can detect packages that make outbound calls, which is a common theme for hijacked packages.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: