logoalt Hacker News

dns_snektoday at 2:03 PM3 repliesview on HN

> since a bunch of people responding with "every package manager can be hit!!!" npm, by design, allows all packages to run package supplied arbitrary code as the logged-in user after an update completes.

This is semi-common and in no way unique to NPM.


Replies

Ajedi32today at 2:25 PM

And even in the ones that don't, having to wait until the project executes to begin its attack is a minor inconvenience for malware.

an0maloustoday at 2:45 PM

What other package managers do this? I don’t think Ruby does

show 3 replies
matheusmoreiratoday at 2:52 PM

You're right. I said the same thing and got downvoted too. Don't let it discourage you.