Hacker News new | ask | show | jobs
Malicious node-IPC Versions Published to NPM (github.com)
6 points by varunsharma07 29 days ago
2 comments

Not again and it is NPM once more.

> Any project that installs one of these versions, directly or transitively, will pull the compromised release.

Hope you have pinned your dependencies in your package.json.

What a disaster.

Why why why it's npm, almost always?