NPM packages disguised as Roblox API code caught carrying ransomware

veti Silver badge

Why does "low barriers" have to mean "no screening"?

Surely most contributors would be OK with a delay before their code was published, while it gets screened for known malware

