<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[NPM verseucht]]></title><description><![CDATA[<p dir="auto">ich habe gerade einen Artikel gelesen<br />
<a href="https://www.heise.de/amp/news/Unbekannte-infiltrieren-Paketmanager-npm-und-verseuchen-Tools-mit-Schadcode-6260153.html" rel="nofollow ugc">https://www.heise.de/amp/news/Unbekannte-infiltrieren-Paketmanager-npm-und-verseuchen-Tools-mit-Schadcode-6260153.html</a><br />
und frage mich, in wieweit uns das trifft.<br />
Gruß,<br />
Mathias</p>
]]></description><link>https://forum.iobroker.net/topic/49236/npm-verseucht</link><generator>RSS for Node</generator><lastBuildDate>Thu, 28 May 2026 05:46:46 GMT</lastBuildDate><atom:link href="https://forum.iobroker.net/topic/49236.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 10 Nov 2021 07:27:42 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to NPM verseucht on Wed, 10 Nov 2021 18:40:50 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/homoran" aria-label="Profile: homoran">@<bdi>homoran</bdi></a> OK Oh <img src="https://forum.iobroker.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f631.png?v=ba16ebd4856" class="not-responsive emoji emoji-android emoji--scream" style="height:23px;width:auto;vertical-align:middle" title=":scream:" alt="😱" />  - erwischt - wie sich Beiträge in den Threads alle paar Stunden wiederholen können. <img src="https://forum.iobroker.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f632.png?v=ba16ebd4856" class="not-responsive emoji emoji-android emoji--astonished" style="height:23px;width:auto;vertical-align:middle" title=":astonished:" alt="😲" /><br />
Ich bin schuldig und bitte um Entschuldigung. Wer im Glashaus sitzt, sollte nicht mit Steinen werfen. ;)</p>
]]></description><link>https://forum.iobroker.net/post/701360</link><guid isPermaLink="true">https://forum.iobroker.net/post/701360</guid><dc:creator><![CDATA[mickym]]></dc:creator><pubDate>Wed, 10 Nov 2021 18:40:50 GMT</pubDate></item><item><title><![CDATA[Reply to NPM verseucht on Wed, 10 Nov 2021 18:37:18 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/mickym" aria-label="Profile: mickym">@<bdi>mickym</bdi></a><br />
<a class="plugin-mentions-user plugin-mentions-a" href="/user/homoran" aria-label="Profile: homoran">@<bdi>homoran</bdi></a> sagte in <a href="/post/701030">NPM verseucht</a>:</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/mathiasj" aria-label="Profile: mathiasj">@<bdi>mathiasj</bdi></a> <a href="https://forum.iobroker.net/topic/49190/schadcode-in-npm-paketen-laut-heise?_=1636531240879">https://forum.iobroker.net/topic/49190/schadcode-in-npm-paketen-laut-heise?_=1636531240879</a></p>
</blockquote>
]]></description><link>https://forum.iobroker.net/post/701358</link><guid isPermaLink="true">https://forum.iobroker.net/post/701358</guid><dc:creator><![CDATA[Homoran]]></dc:creator><pubDate>Wed, 10 Nov 2021 18:37:18 GMT</pubDate></item><item><title><![CDATA[Reply to NPM verseucht on Wed, 10 Nov 2021 18:35:39 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/mathiasj" aria-label="Profile: mathiasj">@<bdi>mathiasj</bdi></a> Interessant - wie sich alle paar Tage die Threads wiederholen - insbesondere wo man noch nicht mal Monate zurück schauen muss. ;)<br />
<a href="https://forum.iobroker.net/topic/49190/schadcode-in-npm-paketen-laut-heise">https://forum.iobroker.net/topic/49190/schadcode-in-npm-paketen-laut-heise</a></p>
]]></description><link>https://forum.iobroker.net/post/701356</link><guid isPermaLink="true">https://forum.iobroker.net/post/701356</guid><dc:creator><![CDATA[mickym]]></dc:creator><pubDate>Wed, 10 Nov 2021 18:35:39 GMT</pubDate></item><item><title><![CDATA[Reply to NPM verseucht on Wed, 10 Nov 2021 17:39:51 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/meister-mopper" aria-label="Profile: meister-mopper">@<bdi>meister-mopper</bdi></a> sagte in <a href="/post/701165">NPM verseucht</a>:</p>
<blockquote>
<p dir="auto">ich dachte wegen 2.0.3</p>
</blockquote>
<p dir="auto">Da ist <strong>iobroker.inst</strong>@2.0.3, nicht coa!</p>
]]></description><link>https://forum.iobroker.net/post/701337</link><guid isPermaLink="true">https://forum.iobroker.net/post/701337</guid><dc:creator><![CDATA[AlCalzone]]></dc:creator><pubDate>Wed, 10 Nov 2021 17:39:51 GMT</pubDate></item><item><title><![CDATA[Reply to NPM verseucht on Wed, 10 Nov 2021 11:59:07 GMT]]></title><description><![CDATA[<p dir="auto">Auch OK</p>
<pre><code>C:\Program Files\iobroker\Test2&gt;npm list coa
iobroker.inst@2.0.3 C:\Program Files\iobroker\Test2
`-- (empty)


C:\Program Files\iobroker\Test2&gt;npm list rc
iobroker.inst@2.0.3 C:\Program Files\iobroker\Test2
`-- iobroker.discovery@2.7.0
  `-- serialport@9.2.0
    `-- @serialport/bindings@9.2.0
      `-- prebuild-install@6.1.4
        `-- rc@1.2.8


C:\Program Files\iobroker\Test2&gt;
</code></pre>
]]></description><link>https://forum.iobroker.net/post/701166</link><guid isPermaLink="true">https://forum.iobroker.net/post/701166</guid><dc:creator><![CDATA[sigi234]]></dc:creator><pubDate>Wed, 10 Nov 2021 11:59:07 GMT</pubDate></item><item><title><![CDATA[Reply to NPM verseucht on Wed, 10 Nov 2021 11:55:22 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/homoran" aria-label="Profile: homoran">@<bdi>homoran</bdi></a> und <a class="plugin-mentions-user plugin-mentions-a" href="/user/mathiasj" aria-label="Profile: MathiasJ">@<bdi>MathiasJ</bdi></a><br />
Okay, ich dachte wegen 2.0.3. Dann ist gut <img src="https://forum.iobroker.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f60a.png?v=ba16ebd4856" class="not-responsive emoji emoji-android emoji--blush" style="height:23px;width:auto;vertical-align:middle" title=":blush:" alt="😊" /></p>
]]></description><link>https://forum.iobroker.net/post/701165</link><guid isPermaLink="true">https://forum.iobroker.net/post/701165</guid><dc:creator><![CDATA[Meister Mopper]]></dc:creator><pubDate>Wed, 10 Nov 2021 11:55:22 GMT</pubDate></item><item><title><![CDATA[Reply to NPM verseucht on Wed, 10 Nov 2021 11:54:12 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/meister-mopper" aria-label="Profile: meister-mopper">@<bdi>meister-mopper</bdi></a><br />
auch bei Dir ist alles sauber!</p>
]]></description><link>https://forum.iobroker.net/post/701164</link><guid isPermaLink="true">https://forum.iobroker.net/post/701164</guid><dc:creator><![CDATA[MathiasJ]]></dc:creator><pubDate>Wed, 10 Nov 2021 11:54:12 GMT</pubDate></item><item><title><![CDATA[Reply to NPM verseucht on Wed, 10 Nov 2021 11:52:18 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/meister-mopper" aria-label="Profile: meister-mopper">@<bdi>meister-mopper</bdi></a> sagte in <a href="/post/701160">NPM verseucht</a>:</p>
<blockquote>
<p dir="auto">Bedeutet das, ich muss sie jetzt komplett neu aufsetzen?</p>
</blockquote>
<p dir="auto">warum?</p>
<p dir="auto">@david-g sagte in <a href="/post/701144">NPM verseucht</a>:</p>
<blockquote>
<p dir="auto">rc   1.2.9, 1.3.9, 2.3.9</p>
</blockquote>
]]></description><link>https://forum.iobroker.net/post/701163</link><guid isPermaLink="true">https://forum.iobroker.net/post/701163</guid><dc:creator><![CDATA[Homoran]]></dc:creator><pubDate>Wed, 10 Nov 2021 11:52:18 GMT</pubDate></item><item><title><![CDATA[Reply to NPM verseucht on Wed, 10 Nov 2021 11:51:08 GMT]]></title><description><![CDATA[<p dir="auto">Meine drei ioBroker-hosts sehen alle so aus:</p>
<pre><code>thomas@rpizigbee:/opt/iobroker $ npm list coa
iobroker.inst@2.0.3 /opt/iobroker
└── (empty)

thomas@rpizigbee:/opt/iobroker $ npm list rc
iobroker.inst@2.0.3 /opt/iobroker
└─┬ iobroker.zigbee@1.5.6
  ├─┬ zigbee-herdsman@0.13.110
  │ └─┬ @serialport/bindings@9.0.4
  │   └─┬ prebuild-install@6.0.1
  │     └── rc@1.2.8 
  └─┬ zigbee-herdsman-converters@14.0.162
    └─┬ zigbee-herdsman@0.13.107
      └─┬ @serialport/bindings@9.0.4
        └─┬ prebuild-install@6.0.1
          └── rc@1.2.8
</code></pre>
<p dir="auto">Bedeutet das, ich muss sie jetzt komplett neu aufsetzen?</p>
]]></description><link>https://forum.iobroker.net/post/701160</link><guid isPermaLink="true">https://forum.iobroker.net/post/701160</guid><dc:creator><![CDATA[Meister Mopper]]></dc:creator><pubDate>Wed, 10 Nov 2021 11:51:08 GMT</pubDate></item><item><title><![CDATA[Reply to NPM verseucht on Wed, 10 Nov 2021 11:52:11 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/homoran" aria-label="Profile: homoran">@<bdi>homoran</bdi></a><br />
ich bin gerade dran.<br />
Ich habe maximal die 1.2.8 auch hier alles sauber.<br />
bei <a class="plugin-mentions-user plugin-mentions-a" href="/user/dondaik" aria-label="Profile: dondaik">@<bdi>dondaik</bdi></a> auch :)</p>
]]></description><link>https://forum.iobroker.net/post/701152</link><guid isPermaLink="true">https://forum.iobroker.net/post/701152</guid><dc:creator><![CDATA[MathiasJ]]></dc:creator><pubDate>Wed, 10 Nov 2021 11:52:11 GMT</pubDate></item><item><title><![CDATA[Reply to NPM verseucht on Wed, 10 Nov 2021 11:40:45 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/mathiasj" aria-label="Profile: mathiasj">@<bdi>mathiasj</bdi></a> sagte in <a href="/post/701137">NPM verseucht</a>:</p>
<blockquote>
<p dir="auto">nach welchen Modulnamen soll ich jetzt genau suchen?</p>
</blockquote>
<p dir="auto">steht zum einen in dem von dir verlinkten Heise Artikel, zum anderen hat <a class="plugin-mentions-user plugin-mentions-a" href="/user/thomas-braun" aria-label="Profile: Thomas-Braun">@<bdi>Thomas-Braun</bdi></a> das in dem von mir verlinkten Thread ausführlich erklärt</p>
]]></description><link>https://forum.iobroker.net/post/701150</link><guid isPermaLink="true">https://forum.iobroker.net/post/701150</guid><dc:creator><![CDATA[Homoran]]></dc:creator><pubDate>Wed, 10 Nov 2021 11:40:45 GMT</pubDate></item><item><title><![CDATA[Reply to NPM verseucht on Wed, 10 Nov 2021 11:26:02 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/mathiasj" aria-label="Profile: mathiasj">@<bdi>mathiasj</bdi></a></p>
<pre><code>Diese Versionen sind manipuliert
Auf den jeweiligen Github-Seiten von coa (Command Line Parser) und rc (Configuration Loader) listen die Repository-Verantwortlichen die mit Schadcode versuchten Versionen auf:

coa
2.0.3, 2.0.4, 2.1.1, 2.1.3, 3.0.1, 3.1.3

rc
1.2.9, 1.3.9, 2.3.9
</code></pre>
]]></description><link>https://forum.iobroker.net/post/701144</link><guid isPermaLink="true">https://forum.iobroker.net/post/701144</guid><dc:creator><![CDATA[David G.]]></dc:creator><pubDate>Wed, 10 Nov 2021 11:26:02 GMT</pubDate></item><item><title><![CDATA[Reply to NPM verseucht on Wed, 10 Nov 2021 11:11:20 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/thomas-braun" aria-label="Profile: thomas-braun">@<bdi>thomas-braun</bdi></a><br />
nach welchen Modulnamen soll ich jetzt genau suchen?<br />
Mein Wunsch ist es, nur eine Warnung auszusprechen.<br />
da ich jedesmal updates mache, und ich nicht weiß, seit wann npm kompromitiert ist, sollte jeder mal nachschauen, ob es ihn erwischt hat.</p>
]]></description><link>https://forum.iobroker.net/post/701137</link><guid isPermaLink="true">https://forum.iobroker.net/post/701137</guid><dc:creator><![CDATA[MathiasJ]]></dc:creator><pubDate>Wed, 10 Nov 2021 11:11:20 GMT</pubDate></item><item><title><![CDATA[Reply to NPM verseucht on Wed, 10 Nov 2021 08:11:42 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/mathiasj" aria-label="Profile: mathiasj">@<bdi>mathiasj</bdi></a> <a href="https://forum.iobroker.net/topic/49190/schadcode-in-npm-paketen-laut-heise?_=1636531240879">https://forum.iobroker.net/topic/49190/schadcode-in-npm-paketen-laut-heise?_=1636531240879</a></p>
]]></description><link>https://forum.iobroker.net/post/701030</link><guid isPermaLink="true">https://forum.iobroker.net/post/701030</guid><dc:creator><![CDATA[Homoran]]></dc:creator><pubDate>Wed, 10 Nov 2021 08:11:42 GMT</pubDate></item><item><title><![CDATA[Reply to NPM verseucht on Wed, 10 Nov 2021 07:42:42 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/mathiasj" aria-label="Profile: mathiasj">@<bdi>mathiasj</bdi></a></p>
<p dir="auto">Die verwendeten Module können in jeder Installation halt anders sein. Da kannst du nur selber schauen. Oder was ist jetzt dein Ansatz oder Wunsch?</p>
<p dir="auto">Bei mir ist eines der beiden Module im Einsatz (bei mehreren Adaptern), aber in älteren Versionen.</p>
]]></description><link>https://forum.iobroker.net/post/701024</link><guid isPermaLink="true">https://forum.iobroker.net/post/701024</guid><dc:creator><![CDATA[Thomas Braun]]></dc:creator><pubDate>Wed, 10 Nov 2021 07:42:42 GMT</pubDate></item><item><title><![CDATA[Reply to NPM verseucht on Wed, 10 Nov 2021 07:30:48 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/thomas-braun" aria-label="Profile: thomas-braun">@<bdi>thomas-braun</bdi></a><br />
da sollte aber nicht nur ich schauen, wenn einer betroffen ist, sind es alle.</p>
]]></description><link>https://forum.iobroker.net/post/701023</link><guid isPermaLink="true">https://forum.iobroker.net/post/701023</guid><dc:creator><![CDATA[MathiasJ]]></dc:creator><pubDate>Wed, 10 Nov 2021 07:30:48 GMT</pubDate></item><item><title><![CDATA[Reply to NPM verseucht on Wed, 10 Nov 2021 07:29:36 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/mathiasj" aria-label="Profile: mathiasj">@<bdi>mathiasj</bdi></a><br />
Musst du selber mal schauen.</p>
<pre><code>cd /opt/iobroker
npm list MODULNAME
</code></pre>
]]></description><link>https://forum.iobroker.net/post/701022</link><guid isPermaLink="true">https://forum.iobroker.net/post/701022</guid><dc:creator><![CDATA[Thomas Braun]]></dc:creator><pubDate>Wed, 10 Nov 2021 07:29:36 GMT</pubDate></item></channel></rss>