@packtwebdevpro
Web Dev Pro by Packt
6 days
Supply chain watch: a malicious npm package mimicking an ESLint plugin used a hidden prompt + postinstall script to steal env vars (tokens/keys). Audit deps + lock installs. 🔗
0
1
0