Or: "That time someone tried to turn my innocent Node.js repo into a credential-harvesting machine"




So there I was, minding my own business with my trusty old Node.js REST API project, when I noticed something weird in the package-lock.json file from one of a PR from a random contributor - and another contributor actually approved the PR right...