
technologyDec 5, 20181:08:43pending
The insider perspective on the event-stream compromise (Interview)
About this episode
Adam and Jerod talk with Dominic Tarr, creator of event-stream, the IO library that made recent news as the latest malicious package in the npm registry. event-stream was turned malware, designed to target a very specific development environment and harvest account details and private keys from Bitcoin accounts.
They talk through Dominic’s backstory as a prolific contributor to open source, his stance on this package, his work in open source, the sequence of events around the hack, how we can and should handle maintainer-ship of open source infrastructure over the full life-cycle of the code’s usefulness, and what some best practices are for moving forward from this kind of attack.
Get every episode summarized
Each time The Changelog: Software Development, Open Source publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from The Changelog: Software Development, Open Source

Forking Cal.com to closed source (Interview)
The Changelog: Software Development, Open Source
Sep 3, 20261:54:32completed

Postgres at PlanetScale (Interview)
The Changelog: Software Development, Open Source
Aug 25, 20261:42:17pending

Canary tokens and digital tripwires (Interview)
The Changelog: Software Development, Open Source
Jul 21, 20262:06:48pending

From open source hits to OpenAI (Interview)
The Changelog: Software Development, Open Source
Jun 5, 20261:46:28pending