When “Everything” Goes Wrong: NPM Dependency-Hell Campaign – 2024 Edition
Happy New Year! What a way to open 2024! NPM user account gdi2290, aka PatrickJS, published a troll campaign to the NPM registry by uploading a package named “everything”, which relies on every other public NPM package, resulting in millions of transitive dependencies. This