Another supply chain nightmare. NPM really needs to step up with stronger safeguards, since these attacks are getting caught quickly but keep happening.
Agreed. The pishing email that started this went to thousands of popular maintainers. We shouldn't be in a position that one phishing email has the power to destroy the world. https://github.com/orgs/community/discussions/172738