
IronWorm: the attack that steals credentials and transforms npm into an entry door for malicious packages
A new attack on the npm supply chain has again revealed that package repositories and automated CI flows are privileged targets for actors seeking access to credentials and secret…







