Hopefully, the client I work for wasn't affected by . The collective decision on that project was to use as few JS as possible and not use NodeJS at all.

AFAIK, this is the third time I've seen the ecosystem get pwned and I don't know if it's because it's popularity makes it a target of choice or if it has always been broken.

Also, I can't find any info as whether pre-commit may be an attack vector. After some hook install a environment.

0

If you have a fediverse account, you can quote this note from your own instance. Search https://mastodon.social/ap/users/115548899905014920/statuses/115616640666467916 on your instance and quote it. (Note that quoting is not supported in Mastodon.)