←back to thread

1208 points jamesberthoty | 1 comments | | HN request time: 0.203s | source
Show context
rpodraza ◴[] No.45277340[source]
Someone should eradicate the npm ecosystem and start from scratch. No sane package manager would allow to run arbitrary scripts or download stuff from God knows where, like random github repos.
replies(1): >>45277556 #
1. Aperocky ◴[] No.45277556[source]
npm is now a private company right? It does also look like they have already gone through enshittification and don't even seem to have publicly acknowledged this attack.