Live data from Hacker News

Keyv and friends compromised in active Shai-Hulud supply chain attack

aikido.dev

141–145 of 145 posts

Re: Keyv and friends compromised in active Shai-Hulud supply chain attack

#141
post #23

I think npm can use chatgpt/claude for each published package to detect these types of attack? And if it sees they can restrict the package from making any changes.

the remedy is worse than the disease

why is it the case? Security isn't a binary thing.

Re: Keyv and friends compromised in active Shai-Hulud supply chain attack

#143
post #139

Earlier quoted context omitted.

Nobody is saying NPM is unique - it’s one end of a spectrum but that doesn’t mean everything else is completely on the other end - for example, this study found Maven projects having almost as many dependencies on average as NPM, both well ahead of everything else: https://arxiv.org/html/2512.14739v1 Again, this is about culture rather than some innate flaw. Dependencies are about trust and I suspect that future deve…

> No way to prevent this says only package manager where this regularly happens "only"

That’s a joke referring to The Onion, not a serious analysis:

https://theonion.com/no-way-to-prevent-this-says-only-nation...

Re: Keyv and friends compromised in active Shai-Hulud supply chain attack

#144
post #143

Earlier quoted context omitted.

> No way to prevent this says only package manager where this regularly happens "only"

That’s a joke referring to The Onion, not a serious analysis: https://theonion.com/no-way-to-prevent-this-says-only-nation...

How much am I expected to charitably interpret the joke? They said "only", I'm taking it at face value because it's obviously intended to be commentary and the obvious implication is that this issue is unique to NPM (as that's the whole point of the Onion article).

I'm well aware of the Onion reference.

Post reply on HN