Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Not really different from any other typo-squatting (e.g. domains).


Except that in this case you're installing software on your computer, not just visiting a webpage.


You might also be downloading the software from a webpage. ;)


That would still be a two-step process (downloading from the browser and then manually executing it).

`npm install` runs code as part of the initial step.

Also, `npm install foo` will of course not just run code from `foo` but from all its dependencies and their dependencies dependencies as well.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: