Follow

Fortunately, spread of trojanized packages is limited to newly built applications only because nobody updates NPM libs anyway πŸ€·β€β™‚οΈ

So as long everyone sticks to the tried strategy of "lets hold and wait if others get infected" we don't need any package signatures etc

zdnet.com/article/malicious-np

Β· Β· 0 Β· 2 Β· 1
Sign in to participate in the conversation
Mastodon πŸ” privacytools.io

Fast, secure and up-to-date instance. PrivacyTools provides knowledge and tools to protect your privacy against global mass surveillance.

Website: privacytools.io
Matrix Chat: chat.privacytools.io
Support us on OpenCollective, many contributions are tax deductible!