The malicious package uses a Python startup hook and obfuscated JavaScript to steal developer and cloud credentials, while sharing infrastructure with earlier Shai-Hulud attacks.
45d ago
verifying reliability
No specialized terms available for this topic.