From package to postinstall payload: Inside the Mastra npm supply chain compromise (opens in new tab)
A poisoned npm package infected 140+ projects with a hidden payload. This report highlights how to detect, hunt, and defend against supply chain attacks using Microsoft Defender and actionable threat intelligence. The post appeared first on .
Read the original article