Researchers Uncover 287 Malicious npm Packages Stealing Developer Credentials in Ongoing Supply Chain Attack
Nearly 300 malicious npm packages stole developer credentials via typosquatting (fake package names like "lodahs" for "lodash") and dependency confusion. The attack targeted Fortune 500 companies and government contractors, accumulating over 4 million installations before removal.