Inside a 176-Package npm Campaign Built to Beat Your Internal Dependencies (opens in new tab)
A 176-package npm malware campaign used dependency confusion and install-time scripts to steal credentials and compromise developer and CI/CD environments.
Read the original article