|
|
|
|
|
by crashedsnow
2896 days ago
|
|
If the hacker has your password, don't they also have the ability to publish a public key used to verify the signed package? It presumably would protect against distribution of a fake package outside of NPM, but if your NPM account is hosed isn't it too late? |
|