TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Embedded malware in ua-parser-JS (NPM package)

3 pointsby carbonboarderover 3 years ago

1 comment

chrismellerover 3 years ago
I’m a (begrudging) TS&#x2F;Node developer who has previously spent over a decade in the .Net ecosystem, and I would like to point out that this kind of @&amp;&#x2F;%} doesn’t happen in other ecosystems.<p>It should <i>not</i> take a 3rd party like GitHub to notify you that there’s a security hole in a hugely popular package. If the NPM registry can’t do any better self-policing than they already do, they should at least start tagging packages with “verified” or “official” like Docker does.<p>I would also say they should start advocating for experienced developers. The “even or odd” package getting hacked should have been a call to order, but apparently it wasn’t.