Information security
fromThe Hacker News
5 hours agoMini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account
A compromised npm maintainer account pushed trojanized @antv and related packages, embedding credential-stealing code and creating significant downstream exposure for auto-updating dependencies.