Hacker News new | ask | show | jobs
by throw-12-16 167 days ago
It gets even worse when you realize most extensions ship bundled node_modules and are a very juicy target for supply chain attacks.