Hacker News new | ask | show | jobs
by LelouBil 208 days ago
Yes and no, usually when malicious packages go public it's some third party cybersecurity firm that scans packages that found it.