• kumi@feddit.online
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      15 hours ago

      Of course.

      As Arch becomes mainstream and more of an attractive target for attackers I think we will get more of the same thing happening regularly in NPM: Legitimate popular packages getting compromised because a maintainer got infected or phished.

      As well as botting of votes and comments.