If you someone made a concerted effort to put malware in a low level npm package, how hard would it be to detect?
Worryingly, it would be really difficult.
miniblog.
Related Posts
It's worryingly easy to disregard empirical evidence, if it supports a viewpoint that differs from our friends: http://t.co/HceBUrgu11
Pip is worryingly tolerant of conflicting version numbers: http://t.co/J3VNfeKW
