Earmark suddenly retired all versions in hex.pm - supply chain attack? - Chit Chat / Alerts - Elixir Programming Language Forum
Today, without any announcement, Earmark has retired all of its versions in hex.pm. This broke mix hex.audit on any project using Earmark (I’d assume a large majority of projects). This was all done by a new maintainer who was also just added today. The retirement message recommends that you migrate to mdex, which is a markdown parser that uses a Rust NIF. Given that there was no announcement, this very much smells to me like a supply chain attack. An attacker could have compromised the new mai...