Malicious Postinstall Hook Found Across 700+ GitHub Repositories, Including Packagist and Node.js Projects (opens in new tab)
Socket found a malicious postinstall hook across 700+ GitHub repos, including PHP packages on Packagist and Node.js project repositories.
Read the original article