Hacker News new | ask | show | jobs
by agolio 1217 days ago
The most "aggressive" part is that those sweet package names like "colorslib" are being stolen.
2 comments

My biggest curiosity here is how they generated over a thousand package names ranging from feasible to interesting. I expected gibberish.

Lol, maybe, "chatgpt, give me a thousand feasible pypi package names"?

The names seem to be simple concatenations of random parts like "game", "lib", "vm", "cv", "http".

They do look surprisingly convincing.

Thankfully, they're not actually being stolen because all the packages were already taken down; they're available for legitimate use again: https://pypi.org/project/colorslib/
While I think that _may_ be the right thing to do here... it's a bit worrying as recycling names like that has it's own share of risks.