David Sherret @dsherret.dev · Feb 4

Both of these are also possible using https dependencies in an npm package. Worst part is in some cases the package wouldn't easily be able to be taken down. npm, pnpm, and bun all happily install this kind of stuff—`deno install` errors.

4 likes 1 replies

?

Replies

David Sherret · Feb 4

Several popular npm packages transitively have this problem, including a recent popular one. It's only a matter of time before someone takes advantage of this.