Adam Baldwin Profile picture
🤘EvilPacket✨CSO at C4|@code4rena 🔑prev Okta, Auth0, GitHub, npm, ^Lift Security, Symantec😈BlindXSS pioneer ✨ 2x DEF CON ⬛️badge holder💥npm audit is my fault
Jan 12, 2021 4 tweets 2 min read
ok I've sent out 748 disclosure notifications (pretty sure most bounced). Some of them were well received, others not so much.¯\_(ツ)_/¯Open source is hard & many maintainers are over worked and under appreciated. I've got about 10 more emails to hand craft & deliver and then ... I was initially pretty excited about the find and most peers agreed it was a fun issue with varying severity, but I finally discovered another researcher had found the same thing late last year and they applied it at an even greater scale! (I focused on npm)