Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Spam Package "Attack" on NPM (npmjs.com)
2 points by lenovouser on Aug 20, 2024 | hide | past | favorite | 1 comment


This account is creating weird spam packages on npm. I can't figure out the reason for it, but it seems fairly elaborate. A lot of the packages depend on each other and the packages get updated over months with bullshit commits like here: https://github.com/erboladaiorg/et-itaque/commits/main/

Not sure what to make of it, I first thought it might be related to the Tea project which previously had the creation of spam packages associated with it, but I haven't found any reference to that in the package sources I looked at.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: