Hacker News new | ask | show | jobs
by dale_lakes 335 days ago
The malicious code had nothing to do with the stylus package. One of the maintainers of stylus published malicious code in another package, and GitHub / npmjs response was to nuke ALL packages that he was a maintainer of, including stylus.
1 comments

The sensible action would be to remove only the malicious packages and suspend that account.