Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
undefined | Better HN
0 points
xghryro
1y ago
0 comments
Share
I suppose you think the maintainers shouldn’t have scrutinized those files? Please tell me it’s a joke.
0 comments
default
newest
oldest
ab5tract
1y ago
The person who added the malicious blobs and signed the compromized archives was
literally
a maintainer of the project.
account42
1y ago
Ok, go ahead and scrutinize those files without looking at the injection code that was never in the repo? Can you find anything malicious? Probably not - it looks like random garbage which is what it was claimed to be.
j
/
k
navigate · click thread line to collapse