Node-ipc attack steals crypto developer credentials via npm
Source: Mexc
Published:
<p>Three poisoned versions of node-ipc went live on the npm registry on May 14, according to the blockchain security firm SlowMist. Attackers hijacked a dormant maintainer account and pushed code designed to siphon developer credentials, private keys, exchange API secrets, and more straight from .en