• brucethemoose@lemmy.world
    link
    fedilink
    arrow-up
    15
    ·
    2 days ago

    It seems like some person with a bot just asked to maintain a bunch of orphaned packages, abusing the 2-week waiting period. Right?

    Thats why they used npm; off the shelf, almost “standard practice” credential harvesting malware. Nothing too fancy.