• kumi@feddit.online
          link
          fedilink
          English
          arrow-up
          1
          ·
          edit-2
          15 hours ago

          Of course.

          As Arch becomes mainstream and more of an attractive target for attackers I think we will get more of the same thing happening regularly in NPM: Legitimate popular packages getting compromised because a maintainer got infected or phished.

          As well as botting of votes and comments.