Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Disclosure: I’m the founder of https://socket.dev

npm stats lag. We observed installs while the malicious versions were live for hours before removal. Affected releases we saw: [email protected], @duckdb/[email protected], @duckdb/[email protected], @duckdb/[email protected]. Same payload as yesterday’s Qix compromise. Recommend pinning and avoiding those versions, reviewing diffs, and considering a temporary policy not to auto-adopt fresh patch releases on critical packages until they age.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: