DEV Community

Discussion on: npm package discovered to have bitcoin-stealing backdoor

Collapse
 
yb profile image
yb

My question is... Who codes with the same computer on which he manages his (crypto) currencies?

Everybody from the crypto sphere should know that those kind of attacks will never stop.

Collapse
 
aturingmachine profile image
Vince

The idea was to hit a certain crypto package that used event-stream as a dependency. The code would only execute when run by that package.