Attackers invite targets to collaborate on a project, convincing them to download and run a repository with malicious npm dependencies.
Attackers invite targets to collaborate on a project, convincing them to download and run a repository with malicious npm dependencies.
github.blog
Security alert: social engineering campaign targets technology industry employees - The GitHub Blog
GitHub has identified a low-volume social engineering campaign that targets the personal accounts of employees of technology firms. No GitHub or npm systems were compromised in this campaign. We’re pu...
