rem’s avatarrem’s Twitter Archive—№ 71,313

  1. Sigh. No one should be surprised when malicious packages turn up inside node dependencies, that steal passwords, or install keyloggers, etc. There's no permissioning around the installation process, so there's no surprise when we're installing god knows what on our machines.