logoalt Hacker News

Retr0idyesterday at 12:03 PM1 replyview on HN

They could've pip installed, curl|sh'd or anything else, it's not relevant to the underlying issue.


Replies

notabotiswearyesterday at 12:30 PM

Perhaps there were other vectors, but npm was the one used here.

And yes, this is an AUR issue, but npm being used to host and dissiminate malware is also [a chronic] one, even if separate.