Hi,
the Operations Support Portal and also API Server UI have dependencies to NPM packages. (KB 266000)
Recently, popular npm libraries, such as ua-parser, rc and coa were hijacked and infected with malware.
See Embedded Malware in NPM: Coa, Rc, Ua-parser - FOSSA, Unbekannte infiltrieren Paketmanager npm und verseuchen Tools mit Schadcode | heise online
If packages used by One Identity HTML5 applications were compromised, our fear is that we might be using those packages when compiling One Identity Manager HTML 5 applications. This would compromise the security and integrity of our OIM customer installation, as well as potentially our systems and data.
We are not experts in npm security. Therefore, as One Identity seems to shift more and more to HTML 5, we have the following questions:
- Is that a risk for OIM customers at all?
- If so, how do you mitigate security and integrity risks for npm packages compiled into OIM?
- How is One Identity protecting customers?
Thanks,
Sebastian