←back to thread

1369 points universesquid | 4 comments | | HN request time: 0s | source
1. paulddraper ◴[] No.45169982[source]
Maintainer phished.

Was caught quickly (hours? hard to be sure, the versions have been removed/overwritten).

Attacker owns npmjs.help domain.

replies(1): >>45170159 #
2. DDerTyp ◴[] No.45170159[source]
Noticed that after ten mins, contacted author immediatly and he seems to be working on it / restoring his account / removing malware on published packages.

Kinda "proud" on it haha :D

replies(1): >>45170407 #
3. jbverschoor ◴[] No.45170407[source]
Doesn’t npmjs do things like signing, pinning, and yanking packages, like rubygems?
replies(1): >>45172206 #
4. paulddraper ◴[] No.45172206{3}[source]
Yes