Ivan Ivan@primal.net 7 months ago Anatomy of a Billion-Download NPM Supply-Chain AttackA massive NPM supply chain attack has compromised foundational packages like Chalk, affecting over 1 billion weekly downloads. We dissect the crypt...
mleku mleku@smesh.lol 7 months ago wouldn't happen if imports were just DNS names and references to git commits. like #golang uses.