Hacker News new | ask | show | jobs
by Gigachad 7 days ago
In this case even if you skimmed it you likely would have missed it since the malicious change was adding a new dependency called "atomic-lockfile".