Hijacked npm & Go Packages Deploy Python Infostealer
š High |Ā Source: The Hacker News Attackers have hijacked legitimate npm and Go packages, weaponising them to deploy a Python-based infostealer across Windows, Linux, and macOS. The attack is notable for bypassing npmās lifecycle script execution ā a common detection vector ā by using Visual Studio Code task configurations instead, suggesting deliberate evasion of npm v12 security controls. Any developer or CI/CD pipeline consuming these packages risks credential and secret theft from the compromised host. ...