logoalt Hacker News

HighGoldsteinyesterday at 11:03 PM3 repliesview on HN

Mitigate? Stop using random packages. Prevent? Stop using NPM and similar package ecosystems altogether.


Replies

cromkayesterday at 11:55 PM

That package wasn't any more random than any other NodeJS package. NPM isn't inherently different from, say, Debian repositories, except the latter have oversight and stewardship and scrutiny.

That's what's needed and I am seriously surprised NPM is trusted like it is. And I am seriously surprised developers aren't afraid of being sued for shipping malware to people.

show 2 replies
metaltyphoonyesterday at 11:16 PM

> and similar package ecosystems altogether

Realistically, this is impossible.

show 2 replies
anthkyesterday at 11:25 PM

Does this happen with CPAN?

At least they seemed to have policies:

https://security.metacpan.org/