• kumi@feddit.online
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    3 hours ago

    Of course.

    As Arch becomes mainstream and more of an attractive target for attackers I think we will get more of the same thing happening regularly in NPM: Legitimate popular packages getting compromised because a maintainer got infected or phished.

    As well as botting of votes and comments.