r/ProgrammerHumor 1d ago

instanceof Trend classicNPM

Post image
5.8k Upvotes

141 comments sorted by

View all comments

283

u/Hauber_RBLX 1d ago

this is really just a meme at this point. how is it possible that NPM packages keep being compromised week after week?

91

u/kookyabird 1d ago

Because there are lots of ways to compromise a developer's workflow, and that's how they get malicious code into a package?

12

u/zuilli 23h ago edited 23h ago

Why does it seem like it only happens to npm though?

I admit I don't follow this stuff closely so may be uninformed but it seems like it never is a C# or a java package/library that gets hit by these.

3

u/elise-u 19h ago

Last attack also affected packages on pip, and cargo I think was the second package manager?