logoalt Hacker News

827atoday at 12:57 PM1 replyview on HN

I can't wait for npm/github to do literally anything at all to mitigate these attacks. Literally anything. Have we considered a basic WAF-style block on some postinstall script strings? LLM-assisted code scanning on publish? Is there anyone home? No I suspect not.


Replies

pier25today at 1:18 PM

Third parties can detect compromised packages. It’s ridiculous Microsoft doesn’t.

show 1 reply