"I have heard something similar about javascript two years ago."
Things like this have happened on npm a few times.
"By the way, could this happen with cpan?"
Yes.
In reply to Re^2: OT. Malicious software in PyPI
by marto
in thread OT. Malicious software in PyPI
by parv
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |