Comment by dist-epoch
2 months ago
> Slipping a malicious package into pypi could expose all kinds of juicy, proprietary data
> In July 2024, Bittensor users were the victims of an $8 million hack. The Bittensor hack was an example of a supply chain hack using PyPI. PyPI is a site that hosts packages for the Python programming language
https://www.halborn.com/blog/post/explained-the-bittensor-ha...
Yes, there are hackers on every platform... but it feels like there's an NPM compromise announced about once a week.