A Malicious Disguise: The Threat Lurking in a Popular Code Repository
The npm package "crypto-encrypt-ts" poses as a TypeScript-friendly adaptation of CryptoJS but is actually a malware designed to harvest cryptocurrency and personal data. Despite being downloaded over 1,900 times, the…