Information security
fromArs Technica
3 days agoSoftware packages with more than 2 billion weekly downloads hit in supply-chain attack
Malicious npm packages injected browser code to monitor crypto transfers and replace wallet addresses, while multiple supply-chain attacks exfiltrated authentication secrets across package ecosystems.