Live data from Hacker News

50% of new NPM packages are spam

blog.sandworm.dev

71–80 of 325 posts

Re: 50% of new NPM packages are spam

#71

Spammers are possibly trying to take advantage of npmjs.com domain's high Google rank. I found and reported this spam account [1] with links to download movies. They seem to be using npmjs as a free web host with good SEO. [1] https://www.npmjs.com/~aarilzd

As an aside, something I've seen when reverse-engineering black hat SEO is online casinos sponsoring prominent open source projects in exchange for a sponsorship link. Seems generous until you you realize this also means a huge boost in page rank.

Re: 50% of new NPM packages are spam

#72

Earlier quoted context omitted.

> What to do about bogus projects sponsored by wealthy companies? Does this happen in the real world, rather than as a theoretical concern? As a thought, when a problem is pressing then sometimes it's best to start with a reasonable action then course correct over time. Rather than doing nothing waiting for a perfect solution.

> Does this happen in the real world, rather than be a theoretical concern? Heck yes. 99% of the stuff advertised to me in big money advertising campaigns is stuff that I will never want. If that doesn't count as "bogus projects sponsored by wealthy companies" then I don't know what does.

In the real world, do wealthy companies want to be named on this list of 3 or 4 groups spamming NPM? That’s a lot different than being seen buying a banner ad.

Re: 50% of new NPM packages are spam

#74

Remember this is a Microsoft product. They certainly have the resources to resolve this if they want to.

A Microsoft product doesn't mean the full capacity of the company will be devoted to resolve it. In a big company almost all products have to fight very hard for additional resources, they are not given resources just because the company as a whole made tons of profits.

Exactly this. Don’t blame the team as they’re doing the best they can with their limited resources. However, calling out spam on HN will help convince Microsoft’s leadership to invest in this problem :)

Re: 50% of new NPM packages are spam

#75
post #22

Just think of it, there is a real developer who decided to do this. Spam is immoral, but doing that to an open source repository is your personal all time low.

Yes but they don't care. Some people don't care if they are immoral. That's why you need regulations and punishments to stop them.

Re: 50% of new NPM packages are spam

#76

Remember this is a Microsoft product. They certainly have the resources to resolve this if they want to.

A Microsoft product doesn't mean the full capacity of the company will be devoted to resolve it. In a big company almost all products have to fight very hard for additional resources, they are not given resources just because the company as a whole made tons of profits.

It sounds like you completely missed the last 4 words of my comment.

Re: 50% of new NPM packages are spam

#77
post #22

Just think of it, there is a real developer who decided to do this. Spam is immoral, but doing that to an open source repository is your personal all time low.

> but doing that to an open source repository

meh. It's owned by Microsoft - aside from the regular morals of spam and whatever, I don't think it's especially bad to target a Microsoft property.

How much of the NPM registry actually is open source?

Re: 50% of new NPM packages are spam

#78
post #52
post #41

Earlier quoted context omitted.

As a developer, I want npm package information and docs to show up in search. I frequently prefer pypi or cran results over others because then I can easily tell if it’s a usable package vs just some snippet. Especially cran because it has pretty rigorous entry requirements so being in cran is a signal of at least some minimal quality.

As a developer, I want npm package information and docs to show up in search. What case is there when you want to find a package in NPM, and information about that package, using Google? If you want information about the package then it's find if the NPM package page is missing from the results - so long as you're getting the package's homepage or git repo then that's plenty. From there you can get to it's NPM page.…

> there is no overlap in the Venn diagram of "searching for a package" and "searching for information about a package".

I don't know, if I want information about something, it seems pretty reasonable that I might do my search for that something.

Re: 50% of new NPM packages are spam

#79
post #63

Earlier quoted context omitted.

So true. It's truly sad that some people can hold tight to their cynicism even as they build up their technical skills

The people who do this are likely not American or Western European, likely not from a wealthy background, likely don't have access to high end tech jobs, and probably can't even make 5% of what a Facebook or Google employee makes. These people might feel spite and anger towards the western world for the extreme lavish excess that developers enjoy. It's not hard to imagine a world where developers can learn some skill…

Being jealous isn't a justification for any action

Re: 50% of new NPM packages are spam

#80
post #25

Earlier quoted context omitted.

A lot of counties (like mine) don't have access to global payments. Having a card in Euro or USD requires special paperwork.

From my experience cryptocurrencies are helping countries overcome that. But still, money wouldn't be a solution for this issue.

You'd have to get cryptocoins in the first place, and there are countries which ban all kinds of cryptocurrency (China) or place it behind onerous KYC requirements (EU, US).
Post reply on HN