2 articles about npm
Threat actor group TeamPCP exfiltrated thousands of GitHub internal repositories through a trojanized Nx Console VS Code extension that lived on the marketplace for just 18 minutes.
OpenAI confirms hackers linked to the Shai-Hulud malware campaign breached internal systems through a compromised npm package, exposing code-signing certificates.