
- Over a dozen popular npm packages were compromised in a phishing-based supply chain attack
- The malware targeted crypto users by hijacking wallet addresses during transactions
- Some called it the most widespread npm compromise to date, affecting 2 billion weekly downloads
More than a dozen npm packages with two billion downloads a week were compromised in a supply chain attack that targeted cryptocurrency users.