logoalt Hacker News

skydhashtoday at 9:40 AM1 replyview on HN

They stole the axios's npm keys and they uploaded malicious artifacts. They did not takeover the axios's repo. The issue is with packaging and distribution, not with code.


Replies

pocksuppettoday at 11:58 AM

What's the meaningful distinction between those two things? You imported axios, you got pwned. Same result either way.

show 1 reply