Changing account's email to block-listed domain, automatically bans the account
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.
A repository demonstrating how you can sneak malicious code into Github PRs
Malicious code can be injected into npm projects via lockfiles (package-lock.json or yarn.lock) because these large, machine-generated files are rarely reviewed thoroughly
Hidden GitHub comment link
Cache poisoning attack on the NPM registry rendering packages unavailable