Hacker News new | ask | show | jobs
by WD-42 35 days ago
A lot of the recent npm attacks have been exfiltration from dev machines, which would just as likely from dev dependencies.