Malicious individuals have been seen uploading deceptive alternatives of legitimate npm bundles like eslint-typescript and @types/node that have accumulated a large number of installations on the package repository.
The fraudulent iterations, titled @typescript_eslinter/eslint and types-node, have been designed to install a trojan and fetch secondary payloads, correspondingly.
“Although deceiving with typosquatting attacks,
The fraudulent iterations, titled @typescript_eslinter/eslint and types-node, have been designed to install a trojan and fetch secondary payloads, correspondingly.
“Although deceiving with typosquatting attacks,
