Live data from Hacker News

Malicious packages in NPM evade dependency detection through invisible URL links

csoonline.com

1–3 of 3 posts

Re: Malicious packages in NPM evade dependency detection through invisible URL links

#3
> To every automated security system, these packages show "0 Dependencies."

With all the faults of npm, I fail to see that as npm fault. That sounds honestly like a security system fault. Why would an audit tool ignore a clearly defined dependency?