Over a dozen popular npm packages were compromised in a phishing-based supply chain attack The malware targeted crypto users by hijacking wallet addresses during transactions Some called it the most ...
GitHub, which owns the npm registry for JavaScript packages, says it is tightening security in response to recent attacks.