Post #4380570
2026-08-04 16:33 UTC
That's why you should migrate to #NPM v12, it prevents exactly this kind of attack: https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack
> Every package in the family received two new files, setup.mjs and Math_Symbol.js, along with a "preinstall": "node setup.mjs" entry added to each package.json. Anyone who ran npm install against an affected version would have had setup.mjs execute automatically before their install completed.
Replies (0)
No replies.