• kumi@feddit.online
        link
        fedilink
        English
        arrow-up
        1
        ·
        edit-2
        11 hours ago

        Of course.

        As Arch becomes mainstream and more of an attractive target for attackers I think we will get more of the same thing happening regularly in NPM: Legitimate popular packages getting compromised because a maintainer got infected or phished.

        As well as botting of votes and comments.