A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems ...
A Keyv-linked npm worm poisoned 353 versions across 79 package names, stealing developer and CI credentials while repository ...