Hacker News new | ask | show | jobs
by jacques_chester 1693 days ago
Almost certainly one of these. It's not a typosquatting attack, since it's an existing package. And it's not a repository compromise, since they had to create new versions instead of silently altering an existing version.