single NPM account pushes 600+ compromised packages, used by millions
Source: Cybernews
Published:
<p>Another massive supply chain attack is spreading. Hundreds of compromised NPM packages are being detected, with hackers using stolen secrets to create over 2,200 public GitHub repositories, all because TeamPCP hijacked a single maintainer’s account.</p> <p>Security teams are sounding the alarm ov