Hacker News new | ask | show | jobs
by squidsoup 31 days ago
This was a GitHub Actions hack, nothing related to publishing on npm was compromised.
1 comments

No way to prevent this, says only CI platform (owned by the same company who owns the package manager) where this regularly happens.