TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Node.js malware caught posting IPs, username, and device info on GitHub

31 pointsby axsharmaover 4 years ago

2 comments

Machaover 4 years ago
I find this concerning in the context of the tendency for packages to promote the use of npx commands, where npx will just find and run the missing package name, so a typo means you have now just run different code than that what you intend in one command.
评论 #24664288 未加载
dave_aielloover 4 years ago
Does the npm Security Policy discussed at <a href="https:&#x2F;&#x2F;www.npmjs.com&#x2F;policies&#x2F;security" rel="nofollow">https:&#x2F;&#x2F;www.npmjs.com&#x2F;policies&#x2F;security</a> govern testing of all NodeJS modules that are available via npm, or does this policy relate to the software that provides the operational infrastructure for npm itself?
评论 #24671891 未加载