Get the latest tech news

GitHub pulls pin on npm's auto-run scripts


Shai-Hulud worm exploited exactly this. Better late than never, says everyone except the malware authors

None

Get the Android app

Or read this on The Register

Read more on:

Photo of GitHub

GitHub

Photo of npm

npm

Photo of Pin

Pin

Related news:

News photo

Upcoming breaking changes for npm v12

News photo

Miasma worms its way onto GitHub as attack kit goes open source

News photo

GitHub disables Microsoft repos pushing password-stealing malware