Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

npm removes malware when reported.



Which is repeating that sources matter: curl from a source like Github with a solid abuse process is a very different story than an unknown server.


s/when/if/

Fixed that for you.


I don't believe that changes the meaning.


(sorry, it was an obscure inverted reference to the saying "not if, but when")




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: