Google says AI tools helped fix 1,072 Chrome security bugs across two June releases and surfaced a sandbox flaw hidden in the code for 13 years.
The malicious dependency used an npm “postinstall” command, which automatically runs code when a package is installed. Its obfuscated downloader identified the victim’s operating system and deployed a ...