Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Updating a package every day would take 30 years to catch bi...

Blog post from Socket

Post Details
Company
Date Published
Author
Bradley Meck Farias
Word Count
680
Company Posts That Month
3
Language
English
Hacker News Points
-
Post removed?
No
Summary

In an investigation by Socket Security, the npm package "Binky" raised eyebrows when it was discovered to have an anomalous 11,460 versions published in just four months, suggesting a daily update rate that would take 30 years to match manually. Despite its impressive version count, Binky is a minimal package with only 31 lines of code, primarily referencing another package, "random-seed," which itself is unremarkable. The mystery behind Binky's prolific updates was traced to a PowerShell script in the package's files, which continuously looped to publish new versions by incrementing a counter in the package.json file. This script managed to bypass npm's rate limits to achieve its extraordinary publication frequency, though it has since been halted. The situation highlights the whimsical and curious behaviors some developers exhibit within the npm ecosystem.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.