Socket researchers have uncovered an active npm supply chain attack campaign dubbed SANDWORM_MODE, involving at least 19 typosquatted packages that impersonate popular developer utilities and AI coding tools like Claude Code. Once installed, the malware harvests npm tokens, GitHub credentials, and cloud keys, then uses them to

2m read time From infoworld.com
Post cover image

Sort: