Javascript is not enabled. This site can still works but it'll be more interactive when javascript is enabled.
loading...
Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
cute_boi
6 hours ago
|
on: Keyv and friends compromised in active Shai-Hulud supply chain attack
I think npm can use chatgpt/claude for each published package to detect these types of attack? And if it sees they can restrict the package from making any changes.
reply
wolfi1
6 hours ago
|
parent
the remedy is worse than the disease
reply