3 ms·
> they rug-pulled a popular NPM package. That's within their rights That sounds like malicious activity. That's normally against most terms of service
by viro 5y ago
> they rug-pulled a popular NPM package. That's within their rights
That sounds like malicious activity. That's normally against most terms of service
- sneak 5y agoJust because it's malicious doesn't mean it's against the rules (or should be). He didn't do anything wrong. You should have local mirrors of stuff you rely on.
- viro 5y agoIt's literally a crime. malware is illegal.
- sneak 5y agoNo, it's not. Publishing malware is protected expression in the USA, like all source code (thanks, djb!). Forcing it onto the computers of others is illegal, but as you know that's not what happened here. Pulled, not pushed.
- Macha 5y agoMeh, by that argument a typosquatter that hosts a malware download is not doing anything illegal as the user who made a typo pulled the malware, not pushed.