Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
Gigachad
4 months ago
|
parent
|
context
|
favorite
| on:
Postmortem: TanStack NPM supply-chain compromise
Sure, without exploits they can steal your api keys, read your personal data, and access your browser data. With exploits they can update packages on your computer too.
lrvick
4 months ago
[–]
No exploits needed. A simple shell alias will suffice. See my example in sibling comment.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: