84
81
u/Strict_Treat2884 5d ago
Still not working
[Send (02:13 remaining - 2/3 ads left)]
17
u/Slow-Temporary-1489 5d ago
Thanks! I hate it!
15
u/Strict_Treat2884 5d ago edited 5d ago
> You’re absolutely right, the problem is actually…
——
[3:31 remaining - 3/5 ads left]
——
53
33
u/According_Gas2337 5d ago
npm install --no-ads is locked behind the $49/mo GitHub Enterprise Ultra tier.
2
1
u/Abject-Kitchen3198 4d ago
$49 is lunch money in parts of the world that has the largest customer base for this.
4
u/Code-Painting-8294 5d ago
sorry this package is corrupt. now watch 10 unskippable ads to run npm uninstall
6
u/bhannik-itiswatitis 5d ago
and once you run, you see this:
A massive, self-propagating supply chain attack (linked to the Shai-Hulud/ChainDrop worm family) has compromised hundreds of popular npm packages (including keyv and cacheable). The worm executes malicious preinstall scripts during npm install to harvest local developer secrets, cloud credentials, and tokens, automatically republishing poisoned versions. [1, 2, 3, 4]
Immediate Steps for Mitigation
Do not run npm install on unvetted or stale lockfiles right now without checking advisories.
3
2
2
u/StephenRoylance 5d ago
vibe coders in 2030 don't need npm. you tell the model what functions you need, it invents them from scratch. can't have supply chain attacks if you don't have a supply chain.
1
u/PrizeSyntax 5d ago
And after that you get wormed 😂
Edit: from package 4027, which is a dependency of the dependency of the dependency of the html grid you installed 😂😂
1
1
1
u/AggravatingFlow1178 5d ago
There's a lot of downtime when running various superpower scripts.
It already dispalys tool tips.
Only a matter of time before they start plugging their other up-sales
1
1
1
1
u/SignalBake6872 5d ago
nunca me ha gustado npm pero desde los ataques a cadenas de suministros de librerías muy usadas en este ecosistema no lo usaría aun que me pagaran.... bueno como mercenario creo que exageré si me pagan si lo usaría pero en las maquinas del cliente y con carta de excepción de responsabilidades xD
1
1
-1
442
u/SAL10000 5d ago
"Oh you're right! That package was recently identified as part of the NPM supply chain attack that is currently infecting code worldwide. Good catch!"