Skip to content
TopicTracker
From xeiaso.netView original
TranslationTranslation

"No way to prevent this" say users of only package manager where this regularly happens

Art-template suffered a supply chain attack via NPM, with attackers controlling the repository since 2025 and loading unauthorized JavaScript from third-party domains. The incident highlights that NPM remains the package manager where such supply-chain attacks regularly occur, with developers expressing helplessness about preventing them.

Related stories