Follow the latest coverage, related explainers and connected technology stories.
Microsoft Threat Intelligence analyzed a widespread attack on the npm supply chain in which a credential-stealing worm was hidden inside more than 400 packages published by different entities. The malware collects developer and CI/CD environment secrets, then uses npm and GitHub tokens to republish malicious versions and open additional propagation paths.