logoalt Hacker News

ChrisSDtoday at 6:12 PM1 replyview on HN

But then that shifts the issue. You've now got an opaque binary blob being injected into programs. What if it is malicious?


Replies

mike_hearntoday at 9:21 PM

It may or may not be a problem depending on whether it's actually used, which is still better than "gets you instantly the moment you compile the app". A lot of codepaths and even whole libraries aren't invoked just because a program depends on them.

It doesn't really matter anyway, because nobody is reading anything in their dependencies before it gets downloaded. Malware can also be hiding in plain sight in source code, as this attack and many others shows.