I guess its meant to play a sick joke on some co-workers?
I guess its meant to play a sick joke on some co-workers?
If you were just trying to get people to install it directly you'd go for name collisions / typos / namesquatting in your package name instead.
What you do it fork a popular package that the project uses and make some changes.
Then update the package-lock so that it points to your GitHub fork.
This file is normally ignored in PR due to the amount of line changes in there so you can have quite a bit of fun.
For now it only supports yarn, but npm support shouldn’t be too hard.
They could also write tutorial or stackoverflow answers linking those packages, it would definitely pass the moderation as the rest of the code would be okay and people copy/paste a lot.
Or maybe they are just assessing what's possible. (or wrote for this article)