2B Weekly Downloads at Risk: Supply Chain Attack Targets Popular npm Packages, Security Leaders Discuss
Eighteen widely used npm packages were compromised via a maintainer's phishing-induced 2FA breach, risking a supply-chain attack across millions of weekly downloads.
Developers face a torrent of malware threats as malicious open source packages surge 188%
"Attackers are no longer simply experimenting with open source. The numbers are telling us that threat actors have identified data as the most profitable target, and developers as the easiest way in."