Hacker News new | past | comments | ask | show | jobs | submit login

It is also a rather easy attack vector. Publish an npm package with this code and when people pull it into their project they will have opened up a backdoor.



Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: