https://naugtur.pl
Wouldn't it be great to fearlessly use them like we did back in 2015?
What if a package turns malicious?
"postinstall": "echo 💩 > /etc/hosts"
├─app.ts
├─node_modules
│ ├─@naugtur
│ │ └─evilpackage
| │ ├─evilPlots.js --,
| │ └─package.json |
│ └─typescript 💩
│ ├─lib |
│ | └─tsc.js <-------'
│ └─package.json
└─package.json
@naugtur naugtur.pl
@naugtur naugtur.pl