Ongoing NPM supply chain attack uses binding.gyp to spread like a worm (opens in new tab)
Summary Packages published from this repository contain a malicious binding.gyp and index.js. Anyone running npm install or npm update against any version of the affected packages will trigger exec...
Read the original article