North Korean hackers used an updated version of a known backdoor to target a popular npm package.
Socket uncovers large-scale GitHub spam campaign abusing “Discussions” notifications Fake advisories with bogus CVEs trick ...