Supply-chain attack using invisible code hits GitHub and other repositories

4 points by sibexico


technomancy

The whole "invisible to reviewers omg!" bit feels very sensationist here. There's a call to eval sitting in plain sight! If that's not a screaming red flag I don't know what is.