Hacker News new | past | comments | ask | show | jobs | submit login
Code libraries posted to NPM try to install malware on dev machines (arstechnica.com)
14 points by dangle1 3 months ago | hide | past | favorite | 1 comment



...“This is, once again, a persistent reminder that supply chain attacks are alive and well.”

For NPM, github, etc, we're long past being able to just trust anything online, whether it's malign or just disinformation.

I remember the first time I looked at server logs and nearly soiled myself with all the port scanning, and login hacks. Now, I'm all "meh - scriptkiddies..."

I guess curation has to replace blind trust.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: