DEV Community

Discussion on: Another Npm Package Is Highjacked and It's Your Fault That This Happened

Collapse
 
vonheikemen profile image
Heiker • Edited

Can I blame society or capitalism?

What if behind every npm package there is a team of well payed developers working really hard to mantain the code? That would be nice.


Also, everyone should add ignore-scripts=true to their .npmrc. It will stop npm from running pre-install or post-install scripts.