A new supply chain attack targeting the Node Package Manager (npm) ecosystem is stealing developer credentials and attempting to spread through packages published from compromised accounts.
The Ruby vulnerability is not easy to exploit, but allows an attacker to read sensitive data, start code, and install ...