‘Flooding Dropper’ Is Hitting npm With a Tidal Wave of Malicious Packages

Malicious npm packages are being created and dropped by a 'Flooding Dropper' campaign, making it hard for defenders to keep up. This campaign is automated and generating a wide range of npm accounts. Developers should be cautious when installing packages. It's recommended to use tools that can detect and block malicious packages. This is a significant threat to npm security.

Source →
FeedLens — Signal over noise Last 7 days