@thomrstrom@triangletoot.party
Post #3251032
2026-06-09 15:59 UTC
Most malicious #npm packages steal; #express-timer just deletes your source tree a minute after you install it — and its author fumbled their own online-banking password into the very same tarball; just wow.
It's trivially detectable using existing open-source software too: https://atomdrift.org/discoveries/2026/06/express-timer-self-destruct-wiper/
Replies (0)
No replies.