A malicious npm package reached over 2 million weekly downloads by hiding its payload in a routine library function rather than an install script.
A new npm supply chain campaign is hiding malware inside ordinary JavaScript package code instead of using the usual ...
Malicious npm package indexed-btree impersonated sorted-btree, using nearly 2M weekly downloads to steal data and deliver payloads.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results