|
|
|
|
|
by philplckthun
2050 days ago
|
|
> Despite a short lifespan on the npm portal, the library was downloaded more than 370 times It’s probably worth mentioning that this doesn’t sound like the back door was successful at all. Every package typically has around ~100-200 downloads immediately due to scanners and proxies. This security response of under a day really sounds like a good improvement, although I still wish npm had some support for signatures so trusted packages can be trusted indefinitely. |
|