Post #3300096
2026-06-12 10:16 UTC
attempt to download npm-based payloads during installation
Why npm and not python? It’s installed on every arch system and wouldn’t bring unnecessary attention 🤷
Replies (2)
-
@lemmyvore@feddit.nl 2026-06-12 11:30
Because the NPM is a complete mess and it’s super easy to exploit for supply-chain attacks by sneaking malware into one of the billion dependencies required by most popular packages.
-
@gary_host_laptop@lemmy.ml 2026-06-12 12:09
this is like the 4th npm vulnerability in months, they used that because npm is shit and easy to exploit