4 ms·
Thanks. > Since then, the npm security team has removed all the compromised coa and rc versions to prevent developers from accidentally infecting themselves.
by bluefox 5y ago
Thanks.
> Since then, the npm security team has removed all the compromised coa and rc versions to prevent developers from accidentally infecting themselves.
Removing all trace of evidence is not something "security teams" should do. Instead of sweeping security incidents under the rug (where twitterverse resides), they should at least mention the existence of these versions and that they contain malware on the package page.
- bqkJoKocJz9jz 5y agoThey posted the [version diffs] (https://my.diffend.io/npm/coa/2.0.2/2.0.4)in https://my.diffend.io/npm/coa/2.0.2/2.0.4)in the article. Not sure if this site catches all the changes though.