
Thousands at Risk: Malicious NPM Packages Unleash Stealth Attack on Developers
Over 60 malicious NPM packages, cleverly disguised as trusted tools, slipped past many developers and compromised sensitive information across thousands of systems. Malware used typosquatting—mimicking popular package names—to deceive users, highlighting the risks of open-source software supply chains. Attacks focused on data