How would any normal person know that npmjs.help is phising, but npmjs.com is valid?
It wasn't a "normal person" it was a developer that put this into a README of his package > But beyond the technical aspects, there's something more critical: trust and long-term maintenance. I have been active in open source for over a decade, and I'm committed to keeping Chalk maintained. Smaller packages might seem appealing now, but there's no guarantee they will be around for the long term, or that they won't be…
Shouldn’t this be solved some other ways?