Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
NPM package 'debug' v4.4.2 contains malware
(
social.hackerspace.pl
)
31 points
by
q3k
12 months ago
|
hide
|
past
|
favorite
|
5 comments
davely
12 months ago
|
next
[–]
More and more, I am thinking all my local development environments for Node / JavaScript projects need to be setup in a sandboxed VM.
ChrisArchitect
12 months ago
|
prev
|
next
[–]
A blog post:
https://www.aikido.dev/blog/npm-debug-and-chalk-packages-com...
(
https://news.ycombinator.com/item?id=45169657
)
dylmye
12 months ago
|
prev
|
next
[–]
The two listed collaborators of the debug package have over 700 packages published collectively, many of them with millions of weekly downloads. What could possibly go wrong when their token is compromised?
q3k
12 months ago
|
prev
|
next
[–]
GH issue:
https://github.com/debug-js/debug/issues/1005
TheUnhinged
12 months ago
|
prev
[–]
is-arrayish lmao
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: