• TragicNotCute
    link
    fedilink
    English
    arrow-up
    9
    ·
    12 hours ago

    Not much. In my experience, they will only take action if it’s obvious. I’ve reported a project three times that is serving malware, but they won’t take it down because it’s using a custom .npmrc and the deps hosted there have the malware. It’s easy to see after npm installing, but they don’t seem to want to do that much investigating.