←back to thread

1369 points universesquid | 1 comments | | HN request time: 0s | source
Show context
paulddraper ◴[] No.45169982[source]
Maintainer phished.

Was caught quickly (hours? hard to be sure, the versions have been removed/overwritten).

Attacker owns npmjs.help domain.

replies(1): >>45170159 #
DDerTyp ◴[] No.45170159[source]
Noticed that after ten mins, contacted author immediatly and he seems to be working on it / restoring his account / removing malware on published packages.

Kinda "proud" on it haha :D

replies(1): >>45170407 #
jbverschoor ◴[] No.45170407[source]
Doesn’t npmjs do things like signing, pinning, and yanking packages, like rubygems?
replies(1): >>45172206 #
1. paulddraper ◴[] No.45172206[source]
Yes