/top/
/new/
/best/
/ask/
/show/
/job/
^
slacker news
login
about
←back to thread
NPM debug and chalk packages compromised
(www.aikido.dev)
1369 points
universesquid
| 2 comments |
08 Sep 25 15:37 UTC
|
HN request time: 0s
|
source
https://github.com/advisories/GHSA-8mgj-vmr8-frr6
1.
hofrogs
◴[
09 Sep 25 07:19 UTC
]
No.
45178600
[source]
▶
>>45169657 (OP)
#
This attack could have been so, so much worse. We were saved by the attacker's lack of creativity and competence.
replies(1):
>>45180162
#
ID:
GO
2.
carwyn
◴[
09 Sep 25 10:41 UTC
]
No.
45180162
[source]
▶
>>45178600 (TP)
#
And the author's prompt response.
↑