I write ComfyUI extensions, just got an email that’s obviously a scam. The usual playbook - trick you into installing some shady npm package, or straight up curl a sh script and run it. Didn’t even read the details, but it’s that same old shit. Some people might actually fall for it.
My guess is they’re targeting plugin devs to steal GitHub and ComfyUI Registry credentials, then inject malicious code into extensions and screw over users too. Bottom line, a lot of people don’t realize package managers like npm and pip are basically just curl with extra steps, and scammers exploit that.
Plus the target audience is small, so it slips past spam filters easier. The package is called runaic/aic, delete it if you see it. Anyone know how to report this on npm, let me know.