Live data from Hacker News

Malicious node-IPC Versions Published to NPM

github.com

1–4 of 4 posts

Re: Malicious node-IPC Versions Published to NPM

#3
Not again and it is NPM once more.

> Any project that installs one of these versions, directly or transitively, will pull the compromised release.

Hope you have pinned your dependencies in your package.json.

What a disaster.