
- A popular npm maintainer fell prey to a phishing attack, sharing login credentials with cybercriminals
- The attackers accessed their npm account and pushed malware through a popular package
- They were removed six hours later, but users should still take caution
Experts have warned that ‘is’, an npm package with more than 2.8 million weekly downloads, was also compromised in the same manner, and served malware for roughly six hours.