Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Well, even if it wasn't a post/pre install, even a node library can fork that exact command, upload your home directory, etc.

That's actually the reason it isn't just dangerous if run as root. Many people have huge amounts of sensitive information and data with read and write access.

A library could of course also fetch even more data. One could create an npm based botnet.



Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: