Ten malicious packages mimicking legitimate software projects in the npm registry download an information-stealing component ...
Researchers outline how the PhantomRaven campaign exploits hole in npm to enable software supply chain attacks.