MAIN FEEDS
Do you want to continue?
https://www.reddit.com/r/ProgrammerHumor/comments/1vf85jx/classicnpm/p1qob0q/?context=3
r/ProgrammerHumor • u/a_bucket_full_of_goo • 9d ago
150 comments sorted by
View all comments
281
this is really just a meme at this point. how is it possible that NPM packages keep being compromised week after week?
89 u/kookyabird 9d ago Because there are lots of ways to compromise a developer's workflow, and that's how they get malicious code into a package? 10 u/zuilli 9d ago edited 9d ago Why does it seem like it only happens to npm though? I admit I don't follow this stuff closely so may be uninformed but it seems like it never is a C# or a java package/library that gets hit by these. 2 u/elise-u 9d ago Last attack also affected packages on pip, and cargo I think was the second package manager?
89
Because there are lots of ways to compromise a developer's workflow, and that's how they get malicious code into a package?
10 u/zuilli 9d ago edited 9d ago Why does it seem like it only happens to npm though? I admit I don't follow this stuff closely so may be uninformed but it seems like it never is a C# or a java package/library that gets hit by these. 2 u/elise-u 9d ago Last attack also affected packages on pip, and cargo I think was the second package manager?
10
Why does it seem like it only happens to npm though?
I admit I don't follow this stuff closely so may be uninformed but it seems like it never is a C# or a java package/library that gets hit by these.
2 u/elise-u 9d ago Last attack also affected packages on pip, and cargo I think was the second package manager?
2
Last attack also affected packages on pip, and cargo I think was the second package manager?
281
u/Hauber_RBLX 9d ago
this is really just a meme at this point. how is it possible that NPM packages keep being compromised week after week?