Remix.run Logo
tkel 25 days ago

If you look at the last N npm worms, they all used postinstall scripts.

cluckindan 25 days ago | parent [-]

Is that even true?

tkel 25 days ago | parent [-]

shai-hulud and variants

https://www.stepsecurity.io/blog/mini-shai-hulud-is-back-a-s...

cluckindan 25 days ago | parent [-]

So N=1? 2? 3?

tkel 25 days ago | parent [-]

at least 3 that i can remember off the top my head in these last couple months. If you look further back you will find more.