Comment by elwebmaster

1 month ago

Why is npm still not blocked by every OS on earth is beyond me. These guys will never learn.

Nothing to do with nom itself. This sort of scam would have worked with many different technologies, even a Makefile.

How does npm differ from any other package manager in that sense?

  • They typically don't execute arbitrary code when setting up the project.

    • If a build tool has any support for tests, it can execute arbitrary code, since that is what tests are. I am quite sure Maven's pom.xml can install binary jar into local .m2/repository, and later use it as plugin during generate-sources phase - and that is something an IDE will want to do when opening project. NPM attacks are really product of its popularity (and update churn that community already got used to).

      1 reply →

Because uh every OS on earth has the exact same vulnerabilities? How are you supposed to stop a user from downloading something random from the internet and running it?

npm is hard to avoid, as other ecosystems have integrated it as a cross-platform build/installer script bootstrap.

Indeed, all things nodejs are usually a dumpster fire at a hair salon, but the real point here was people always inherit whatever the previous cheapest labor built at that office. Also, usually people don't get to make architectural decisions for a long time. =3