Remix.run Logo
paulddraper 4 days ago

Maintainer phished.

Was caught quickly (hours? hard to be sure, the versions have been removed/overwritten).

Attacker owns npmjs.help domain.

DDerTyp 4 days ago | parent [-]

Noticed that after ten mins, contacted author immediatly and he seems to be working on it / restoring his account / removing malware on published packages.

Kinda "proud" on it haha :D

jbverschoor 4 days ago | parent [-]

Doesn’t npmjs do things like signing, pinning, and yanking packages, like rubygems?

paulddraper 4 days ago | parent [-]

Yes