Malicious npm packages tied to Arweave used Rust infostealer to steal developer secrets

JFrog linked the campaign to a compromised asteroiddao maintainer account, saying 36 packages were republished with malware that stole credentials and spread through GitHub commits.

Summary

verifying reliability

Terms & Concepts

No specialized terms available for this topic.