logoalt Hacker News

alexjurkiewicztoday at 12:43 AM1 replyview on HN

NPM is getting all the attacks and attention because it is the biggest. But there's nothing language specific to this class of attacks.


Replies

nrmitchitoday at 2:42 AM

Yes, that is clear. But in this particular instance the tanstack packages are downstream of a ton of other packages.

Tanstack infected a bunch of other packages; then resolving their issue doesn’t fix the widespread issue