Hacker News new | ask | show | jobs
by laserlight 1416 days ago
Considering that only clones are affected, your original tweet is downright wrong. None of the listed projects (python, js, bash, docker, k8s) are affected. Anybody can fork a repository to introduce malware.
1 comments

js is a project?
You're right. It's not. I just copy-pasted the list from the tweet. I assume that the author meant to write jq.