Skip to content

Comment on 70% of new NPM packages in last 6 months were spamparent

Comments

But who would use those spam packages in their project? Don't don't do anything.

I don't know if they managed to fix it in recent years, but JS dependencies management used to be broken. I think the left-pad[0] incident is the most known one, but not the unique one. My guess is that you spam enough, at some point in time one of the packages will go viral.

[0] https://en.wikipedia.org/wiki/Npm_left-pad_incident

This was fixed years ago, and of course people then complained about not being able to remove their packages [1].

[1] https://news.ycombinator.com/item?id=38874874

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.