3 ms·
This account is clearly squatting. Not only do they hold several one letter package names but also many other names that are generic. The majority of them have
by mneil 10y ago
This account is clearly squatting. Not only do they hold several one letter package names but also many other names that are generic. The majority of them have nothing more than a package.json
- noobermin 10y agoA new version of website squatting? There can't be very much money in npm package squatting, though.
- WaxProlix 10y agoA fellow poster up a bit mentioned that the empty 'D' package has something like 64k downloads per day. Surely there's money in compromising the systems that this ends up on? Malicious packages are a known point of vulnerability, and with that broad a shot, you're likely to get access to at least a few apps / AWS accounts / whatever.
- deleted 10y ago[deleted]