Or, npm can add trust ratings to packages and versions. And Github the parent company can lend a tiny fraction of resources and programmer power to developing static code analysis tools for npm packages.
This problem is completely solvable in two different ways:
1) everyone uses private feeds that use vetted versions only, and
2) Github/npm take responsibility for every package published to npm as the distributor.
Also the name Shai-hulud was chosen by the people who made the malware, you shouldn't dignify them by using the name they chose.
Or, npm can add trust ratings to packages and versions. And Github the parent company can lend a tiny fraction of resources and programmer power to developing static code analysis tools for npm packages.
This problem is completely solvable in two different ways:
1) everyone uses private feeds that use vetted versions only, and
2) Github/npm take responsibility for every package published to npm as the distributor.
Also the name Shai-hulud was chosen by the people who made the malware, you shouldn't dignify them by using the name they chose.