News

"Each published package becomes a new distribution vector: as soon as someone installs it, the worm executes, replicates, and ...
Qix is an open source maintainer account that was compromised by a phishing attack. This allowed attackers to infect 18 popular npm packages with malicious code. Together, these packages are ...