
Attribution as a trap: a npm attack and the fragility of the software supply chain
The recent reelaboration of the author of the npm package hijacking - which Amazon Threat Intelligence now associates with North Korea - once again puts on the table a known but i…







