NPM
“Just like a human hacker would, they're going to pick the easiest way in, and the lowest hanging fruit now has become just publishing malware to public registries because they know that there's no vetting happening, and developers are likely to install them.”
Source→“About half of our team at Socket are maintainers, half the engineering team. And so we have a lot of connections in the community. And our CTO is the former CTO of NPM.”
Source→“NPM has announced that they are planning to, I think it's in January 2027, going to require human interactive confirmation through 2FA before any new publishers can happen. So that will likely kind of kill this whole worm concept completely.”
Source→AI-extracted from podcast / newsletter / paper summaries. May contain errors.