Coverage of "Npm" on Cryptopasta: the stories and the context behind them.
A stolen GitHub account let attackers inject malware into npm packages downloaded 127 million times weekly, turning trusted credentials into a self-replicating worm.
August 4, 2026