logoalt Hacker News

herpdyderpyesterday at 2:15 PM1 replyview on HN

Also add it to ~/.npmrc!


Replies

hedorayesterday at 4:03 PM

So, I do this because it's universally recommended, but why does it help?

Can't they just jam the malware into the package itself? It runs with the same permissions on my machine (in unit tests, node servers, etc).

show 2 replies