

Comments
Hacker News
Because the Go and Packagist registries don't require additional publishing credentials like NPM and PyPI North Korean threat actors have been able to compromise legitimate packages via their PolinRider campaign.
by 6mile
Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- Because the Go and Packagist registries don't require additional publishing credentials like NPM and PyPI North Korean threat actors have been able to compromise legitimate packages via their PolinRider campaign.by 6mile