Hacker News new | ask | show | jobs
by ryukafalz 1693 days ago
Your periodic reminder that modules have way more authority than they need by default, and that there are ways to fix this: https://medium.com/agoric/pola-would-have-prevented-the-even...

(Of course this malware was in a preinstall script, which should also be disabled... but any module you import in a node app can do bad things when you run your app, preinstall script or no.)