Hacker News new | ask | show | jobs
by vmception 1929 days ago
I thought this would be about the repository maintainers of obscure but used dependencies, who then that sell to random passerbys who then make the dependency malicious

Because I would like to read about that experience