• HubertManne@piefed.social
    link
    fedilink
    English
    arrow-up
    10
    ·
    2 months ago

    holy crap:

    On July 19, 2025, the package’s primary maintainer, John Harband, announced that versions 3.3.1 through 5.0.0 contained malware and were removed roughly 6 hours after threat actors submitted them to npm.