Earlier quoted context omitted.
> presumably this comprise was only found out because a lot of people did update This was supposedly discovered by "Socket researchers", and the product they're selling is proactive scanning to detect/block malicious packages, so I'd assume this would've been discovered even if no regular users had updated. But I'd claim even for malware that's only discovered due to normal users updating, it'd generally be better to…
Better for the cool down to be managed guaranteed centrally by the package forge rather than ad-hoc by each individual client.
Having the forge control it half-defeats the point; the attackers who gained permission to push a malicious release, might well have also gained permission to mark it as "urgent security hotfix, install immediately 0 cooldown".