User avatar
privTri Volpeon areon3NSmol @volpeon@icy.wyvern.rip
1w
The changelog reads “performance improvements.” The package now includes a postinstall script that exfiltrates .npmrc, .pypirc, ~/.cargo/credentials, and ~/.gem/credentials to a server in a country the attacker mistakenly believed had no extradition treaty with anyone.
Ah, the good old post-install script attack vector