Skip to content

Comment on Mischievous NPM Publicationsparent

Comments

Definitely not zero. Security researchers and SSC companies are pretty notorious for self-promotion. I would not be surprised if some of these "detected packages" are from researchers who want attention.

You're not wrong. We (Phylum) have seen and called out a security company for typosquatting a popular package as a means of advertising. It felt gross to impact random devs for marketing...

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.