Comment by vb-8448
2 years ago
I don't know if they managed to fix it in recent years, but JS dependencies management used to be broken. I think the left-pad[0] incident is the most known one, but not the unique one. My guess is that you spam enough, at some point in time one of the packages will go viral.
This was fixed years ago, and of course people then complained about not being able to remove their packages [1].
[1] https://news.ycombinator.com/item?id=38874874