software supply chain
The malicious code creates a 'cascading compromise effect' into dependent ecosystems across npm's registry.
The malware "weaponized AI CLI tools (including Claude, Gemini, and q) to aid in reconnaissance and data exfiltration"
Google's new open source platform will shield popular dependencies with automations and data visibility tools.
"These emails implored OpenJS to take action to update one of its popular JavaScript projects to ‘address any critical vulnerabilities'"