Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
The expired domain name for the 'foreach' NPM package maintainer was bought. (twitter.com/vxunderground)
30 points by pjmlp on May 11, 2022 | hide | past | favorite | 1 comment


The situation with npm package integrity is getting quite ridiculous.

Just to clarify what domain did they let expire? Is this the email in the author field of package.json? So the attack vector is to take that over that domain, run an email server, and reset the account password on npmjs.org?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: