"Although the affected packages were all Composer packages, the malicious code was not added to composer.json," Socket said. "Instead, it was inserted into package.json, targeting projects that ship JavaScript
Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware
"Although the affected packages were all Composer packages, the malicious code was not added to composer.json," Socket said. "Instead, it was inserted into package.json, targeting projects that ship JavaScript
SOCIAL SHARE CARD GENERATOR