Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This was a GitHub Actions hack, nothing related to publishing on npm was compromised.


No way to prevent this, says only CI platform (owned by the same company who owns the package manager) where this regularly happens.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: