Y
Hacker News
new
|
ask
|
show
|
jobs
by
xghryro
815 days ago
I suppose you think the maintainers shouldn’t have scrutinized those files? Please tell me it’s a joke.
2 comments
ab5tract
814 days ago
The person who added the malicious blobs and signed the compromized archives was
literally
a maintainer of the project.
link
account42
810 days ago
Ok, go ahead and scrutinize those files without looking at the injection code that was never in the repo? Can you find anything malicious? Probably not - it looks like random garbage which is what it was claimed to be.
link