you are viewing a single comment's thread
view the rest of the comments
[–] 10 points 2 months ago

Not much. In my experience, they will only take action if it’s obvious. I’ve reported a project three times that is serving malware, but they won’t take it down because it’s using a custom .npmrc and the deps hosted there have the malware. It’s easy to see after npm installing, but they don’t seem to want to do that much investigating.

  • source