https://github.com/oro-os
https://news.ycombinator.com/user?id=junon
I wonder if it really is only npm that got compromised.
https://github.com/oro-os
https://news.ycombinator.com/user?id=junon