Comment npm is a problem (Score 2) 13
npm is a problem. It's this massive, unvetted self-publishing repository without any easy way to verify the origin of packages, and the packages largely get installed directly to production on billions of sites every day without any vetting or review.
It's crazy, like something out of the 90s.
Yes, supply attacks like those carried out against npm are pretty common in general, at the state actor level. There've been a couple fun ones in recent years. But the openness and lack of basic precautions surrounding npm in conjunctions with common development practice just makes it a recipe for disaster.