Hacker News new | ask | show | jobs
by msoad 3734 days ago
Yes, with that you don't even need to "socially fool the package owner". You can use common misspelling for famous packages. It gets you very far.

For example "lowdash" instead of lodash.

1 comments

I wonder if npm has metrics for this - how many times a month are people attempting to "npm install boostrap"?