A malicious npm package reached over 2 million weekly downloads by hiding its payload in a routine library function rather than an install script.
North Korean-linked WaterPlum actors used fake job interviews to infect 30,000+ devices and steal crypto from thousands of ...