A malicious npm package pulled two million weekly downloads while running its payload from ordinary library code instead of an…
The attacker exfiltrated source code and proprietary information from multiple GitHub repositories, prompting an ongoing investigation with law enforcement.
The attack leverages a trojanized npm package to steal credentials from developer environments connected to Bitwarden CLI workflows.
The attack leverages both malicious Docker images on Docker Hub and fake VS Code extensions, requiring developers to verify all…