Comment on The new Chinese owner of the popular Polyfill JS project injects malware into more than 100 thousand sites

<- View Parent
corsicanguppy@lemmy.ca ⁨4⁩ ⁨months⁩ ago

Running npm install would give me a mini heart attack

It should; but more because it installs things right off the net with no validation. Consistency of code product is not the only thing you’re tossing.

source
Sort:hotnewtop