Remix.run Logo
stephantul 4 hours ago

I think this is such an nefariously unnecessary negative argument.

Most, if not all, of the shai-hulud attacks that hit npm and other ecosystems were preventable with cooldowns. And these were not detected because regular users reported the worms, but because security researchers did. I don’t think I’ve ever seen an attack that was discovered because a user reported it.