NPM and other package repositories must learn from Linux distributions.
It is ridiculous that every week we are now reading about vulnerability that already ended up in the NPM package repository.
Linux distributions have mitigated this with for example having testing and stable branches. Packages stay few weeks at least in testing, before they go stable. This would have prevented many of the compromises alone.

axios Compromised on npm - Malicious Versions Drop Remote Access Trojan - StepSecurity
Hijacked maintainer account used to publish poisoned axios releases including 1.14.1 and 0.30.4. The attacker injected a hidden dependency that drops a cross platform RAT. We are actively investigating and will update this post with a full technical analysis.







