Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

These get detected almost immediately, and removed by npm within hours (axios, tanstack at least)


But who will detect them on day one once everyone ignores them for seven days?


These things are usually caught by tools specifically scanning npm or by the maintainers noticing their account is compromised, not by people auditing their own installed packages.


There are some companies that specialize in detecting those, they do it for free (and get lots of marketing for it…)


AI agents




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: