You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I've noticed a huge influx of spam packages on npm, which seem to be trying to game the tea.xyz protocol. All of the ones I've spotted have been created by a template repo which uses github scheduled actions to continuously create new versions. Has anyone else noticed this? This article from web3isgoinggreat from a few months ago goes over the issue, but this seems to be a new wave and hasn't been covered yet. This spam has really made my process for finding hidden gems (as in, good packages, not rubygems) on npm basically impossible.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
-
I've noticed a huge influx of spam packages on npm, which seem to be trying to game the
tea.xyz
protocol. All of the ones I've spotted have been created by a template repo which uses github scheduled actions to continuously create new versions. Has anyone else noticed this? This article from web3isgoinggreat from a few months ago goes over the issue, but this seems to be a new wave and hasn't been covered yet. This spam has really made my process for finding hidden gems (as in, good packages, not rubygems) on npm basically impossible.Beta Was this translation helpful? Give feedback.
All reactions