pull down to refresh
126 sats \ 0 replies \ @rblb 16 Sep
Installing npm packages feels like playing russian roulette these days.
This is 100x times worse than the other attack.
reply
0 sats \ 0 replies \ @MaxAWebster 17 Sep
Time for a new NPM / package registry using nostr keys? And integrating split payments as well! (which @getalby already has working I think).
reply
0 sats \ 0 replies \ @3a42879d5f 16 Sep
So it sounds like it isn't just a supply chain attack anymore-- It's a Trojan horse via supply chain that can replicate. Reminds me of early 2000's viruses.
reply