The largest incident yet is a warning that developers should urgently check package security, say experts.

4 malicious npm packages with 3,006 downloads spread stealers and Phantom Bot, forcing removals and secret rotation.

The largest incident yet is a warning that developers should urgently check package security, say experts.