Hijacked Open-Source Packages Are Deploying a Hidden Infostealer
A supply-chain attack hiding inside everyday developer tools — triggered the moment a project folder is opened Executive Summary Security researchers uncovered a software supply chain attack in which attackers hijacked legitimate npm packages and a cluster of Go packages to quietly install a wide-reaching, Python-based information stealer on developer machines running Windows, Linux, or […]











