Elektrine lite

← Feed

@placebo@lemmy.zip

Post #3300096

2026-06-12 10:16 UTC

attempt to download npm-based payloads during installation Why npm and not python? It’s installed on every arch system and wouldn’t bring unnecessary attention 🤷

Replies (2)

  • @lemmyvore@feddit.nl 2026-06-12 11:30

    Because the NPM is a complete mess and it’s super easy to exploit for supply-chain attacks by sneaking malware into one of the billion dependencies required by most popular packages.

    Open ##3300444

  • @gary_host_laptop@lemmy.ml 2026-06-12 12:09

    this is like the 4th npm vulnerability in months, they used that because npm is shit and easy to exploit

    Open ##3300568