Web Hack List

Later archive addition

CDN Tar Oops

A flaw in unpkg's tar extraction allowed a malicious npm package to create links and write outside its own extraction directory. The resulting cross-package file overwrite could have placed attacker-controlled JavaScript into assets served to thousands of sites, turning an archive bug into a CDN supply-chain compromise.

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of its author, first published at the original source. Preserved copies are kept so the citation survives its host.