Hacker News new | ask | show | jobs
by soheil 1576 days ago
1p runs as the logged in user so does a hypothetical malicious npm package.