Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Does this imply there was unencrypted AWS credentials stored in an NPM repository and/or possibly GitHub?

Large organisation, hundreds of developers. Kind of likely that something is visible somewhere. Still a bit surprising it’s the prod access keys for npm…



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: