npm
1 articles
axios Hit by Supply Chain Attack — Karpathy: Package Manager Defaults Need to Change
axios, npm's most popular HTTP library, was hit by a supply chain attack. Karpathy nearly got caught. His conclusion: individual precautions only go so far — the real fix is changing package manager defaults.