Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

So just to be clear, this is only a problem for npm package maintainers/admins right? Regular users of npm wouldn't have registry accounts. The headline reads as if the npm client is the risk.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: