
technologyDec 5, 20181:08:43pending
The insider perspective on the event-stream compromise
About this episode
Adam and Jerod talk with Dominic Tarr, creator of event-stream, the IO library that made recent news as the latest malicious package in the npm registry. event-stream was turned malware, designed to target a very specific development environment and harvest account details and private keys from Bitcoin accounts.
They talk through Dominic’s backstory as a prolific contributor to open source, his stance on this package, his work in open source, the sequence of events around the hack, how we can and should handle maintainer-ship of open source infrastructure over the full life-cycle of the code’s usefulness, and what some best practices are for moving forward from this kind of attack.
Get every episode summarized
Each time Changelog Interviews publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from Changelog Interviews

Forking Cal.com to closed source
Changelog Interviews
Sep 3, 20261:54:32completed

Postgres at PlanetScale
Changelog Interviews
Aug 25, 20261:42:17pending

Canary tokens and digital tripwires
Changelog Interviews
Jul 21, 20262:06:48pending

From open source hits to OpenAI
Changelog Interviews
Jun 5, 20261:46:28pending