Hacker News new | ask | show | jobs
by clncy 327 days ago
I agree that it seems very improbable. The only possible malicious scenario I can imagine is that the Github repo is clean, but npm creds have been compromised.