A ‘logical flaw’ in the npm registry enabled authors of malicious packages to quietly add anyone and any number of users as ‘maintainers’ to their packages in an attempt to boost the trust in their packages. The GitHub-owned repository of NodeJS components has now fixed the flaw after the issue was responsibly reported by cloud native security company, Aqua.