Hacker News new | ask | show | jobs
by handstitched 278 days ago
OP is the developer & maintainer of the affected packages, so the attacker was able to use their phished credentials to upload compromised versions to NPM.
1 comments

oh! understood. thanks.