Cybersecurity

Malware Injected into 6 npm Packages After Maintainer Tokens Stolen in Phishing Attack

July 20, 2025 1 min read The Hacker News
Article Data

Phishing campaign targeted popular npm packages via a phishing campaign. Project maintainers' tokens were stolen and used to publish malicious versions of the packages to the registry without any source code commits.

Read more on The Hacker News

Loading next article