Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Great. By compromising one package you can access their bank account...


Same thing as compromising one of these packages loaded from a CDN...

If someone loads a bad JS library, it doesn't matter where it came from.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: