#NPM: Two malicious packages were discovered on npm (#NodeJS package manager) that covertly patch legitimate, locally installed packages to inject a persistent reverse shell backdoor:
#SoftwareSupplyChainSecurity
👇
https://www.bleepingcomputer.com/news/security/new-npm-attack-poisons-local-packages-with-backdoors/