3 ms·
And that's how it was compromised: The maintainer whose account was compromised had reused their npm password on several other sites and did not have two-facto
by madethemcry 8y ago
And that's how it was compromised:
The maintainer whose account was compromised had reused their npm password on several other sites and did not have two-factor authentication enabled on their npm account.
I wonder how many accounts the attacker checked before hitting this account. This will definitely get a nice place in the bucket of examples I throw to people, when I see they are still reusing passwords.