←back to thread

1369 points universesquid | 1 comments | | HN request time: 0.23s | source
Show context
cddotdotslash ◴[] No.45170804[source]
NPM deserves some blame here, IMO. Countless third party intel feeds and security startups can apparently detect this malicious activity, yet NPM, the single source of truth for these packages, with access to literally every data event and security signal, can't seem to stop falling victim to this type of attack? It's practically willful ignorance at this point.
replies(5): >>45170982 #>>45172458 #>>45172566 #>>45173494 #>>45175539 #
1. buzuli ◴[] No.45175539[source]
For packages which have multiple maintainers, they should at least offer the option to require another maintainer to approve each publish.