top | item 45277340

(no title)

rpodraza | 5 months ago

Someone should eradicate the npm ecosystem and start from scratch. No sane package manager would allow to run arbitrary scripts or download stuff from God knows where, like random github repos.

discuss

order

Aperocky|5 months ago

npm is now a private company right? It does also look like they have already gone through enshittification and don't even seem to have publicly acknowledged this attack.