Just a normal day in Javascript land.
laughs in elixir
replies(1):
If Hex gets popular enough, it will happen there, too. Even if the install process doesn’t run arbitrary code, when you actually load the library, it can do stuff, so I don’t see any reason to gloat.