Hacker News new | ask | show | jobs
by ricardobeat 2541 days ago
In the example the linter itself is not malicious, but used to deliver a malicious program that can have unrestricted filesystem access. Not vague at all, see recent news on the ‘event-stream’ package being used to steal cryptocurrency wallets.
1 comments

The 'vague' part is not that it doesn't happen - see the comment you are replying to.