Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'd imagine the attacker published a new compromised version of their package, which the author eventually downloaded, which pwned everything else.
 help



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: