I think npm can use chatgpt/claude for each published package to detect these types of attack? And if it sees they can restrict the package from making any changes.
the remedy is worse than the disease
Keyv and friends compromised in active Shai-Hulud supply chain attack
141–145 of 145 posts
Re: Keyv and friends compromised in active Shai-Hulud supply chain attack
#142Re: Keyv and friends compromised in active Shai-Hulud supply chain attack
#143Earlier quoted context omitted.
Nobody is saying NPM is unique - it’s one end of a spectrum but that doesn’t mean everything else is completely on the other end - for example, this study found Maven projects having almost as many dependencies on average as NPM, both well ahead of everything else: https://arxiv.org/html/2512.14739v1 Again, this is about culture rather than some innate flaw. Dependencies are about trust and I suspect that future deve…
> No way to prevent this says only package manager where this regularly happens "only"
https://theonion.com/no-way-to-prevent-this-says-only-nation...
Re: Keyv and friends compromised in active Shai-Hulud supply chain attack
#144Earlier quoted context omitted.
> No way to prevent this says only package manager where this regularly happens "only"
That’s a joke referring to The Onion, not a serious analysis: https://theonion.com/no-way-to-prevent-this-says-only-nation...
I'm well aware of the Onion reference.