logoalt Hacker News

xystyesterday at 6:01 PM0 repliesview on HN

yet another npm supply chain attack, these are becoming as ubiquitous as gun violence in the US.

We have become numb to it.

One of my tools, bruno, was impacted but seems to be limited to cli via npm install [1]

[1] https://github.com/usebruno/bruno/security/advisories/GHSA-6...