| There's also no systemic fix for this issue. Next week, the same thing could happen again. It's time to enforce two-factor authentication for publishing packages. It's time to publish a roadmap towards package signing and verification. It's time to talk about sandboxing the install scripts to prevent token theft. We're done for the day is so far from sufficient. |
You're the first person I've seen mention this, which seems like it should be the first and most obvious line of defense against bad stuff like this. +1