Y
Hacker News
new
|
ask
|
show
|
jobs
by
mplewis
14 days ago
OK, so it looks like you've still added suspicious code to your package.
1 comments
drdexebtjl
14 days ago
You can make it much less suspicious. In particular, if you can compromise the package publishing process, and not just pushes to main, you can add your malicious code to binary artifacts, not to the source code.
link