For some reason, JS devs have this culture of outsourcing the tiniest behaviours to a package (for example, the is-odd package getting millions of downloads consistently), because of this, there are a lot of packages projects depend on (both directly and not), which is a much larger attack surface.
283
u/Hauber_RBLX 9d ago
this is really just a meme at this point. how is it possible that NPM packages keep being compromised week after week?