Follow

@codepo8 Are there any more details anywhere? If the package mentioned at news.ycombinator.com/item?id=4 was indeed the affected version (I don't think there's a way to check, given that it was pulled?), then a quick glance doesn't show anything obviously malicious in the code...

(It's obfuscated, but the obfuscation does not exactly seem to be very strong, and it doesn't seem to make any attempt to hide the identifiers, so you can gather a lot even from the obfuscated code)

· · Web · 1 · 0 · 0
Sign in to participate in the conversation
Pixietown

Small server part of the pixie.town infrastructure. Registration is closed.