|
|
|
|
|
by singulasar
274 days ago
|
|
on the other hand, the previous supply chain attack was found by automated tech.
Also, if MS would be so kind as to just run similar scans at the time a package is updated instead of after the package is updated (which is the only way the automated tech can run if npm doesn't integrate it), then malware like this would be way less common. MS doesn't care |
|
Are you sure about this? Would love to see which ones.