Crypto-stealing malware is permeated by the core JavaScript libraries used by millions
The NPM (Node Packet Manager) account for developer QIX has been compromised, allowing hackers to publish malicious versions of his packages. The attacker has published malicious versions of dozens of extremely popular JavaScript packages, including basic utilities. The hacks have a larger range as the affected packages have a total download of over 1 billion…
