Hacker News new | ask | show | jobs
by grashalm01 3427 days ago
Great. By compromising one package you can access their bank account...
1 comments

Same thing as compromising one of these packages loaded from a CDN...

If someone loads a bad JS library, it doesn't matter where it came from.