Popular npm Libraries Hijacked: Fake Versions Trick Thousands into Downloading Malware
Security researchers discovered malicious npm packages and VSCode extensions targeting developers through sophisticated supply chain attacks. The threats include typosquatted versions of popular packages like typescript-eslint and @types/node, which deploy trojans and malicious payloads. T...
