Skip to content
TopicTracker
From HackerNewsView original
TranslationTranslation

Is this a supply-chain attack attempt?

A GitHub issue on angular-tree-component questions whether a recently merged pull request adding a mysterious "chore" file to several packages is a supply-chain attack attempt. The commit lacks context, appears not to fix anything, and could log installs or hide malicious code.

Related stories

  • The article draws a parallel between Costco's business model—deliberately limiting choices to offer higher quality and value—and how the internet could be structured. It argues that, like Costco, a better internet should prioritize curation, trust, and quality over endless, low-quality options, suggesting that this "intelligent loss of sales" could improve user experience.