Inside a Tor Backed Supply Chain Worm
Reported 20 May 2026 by otx · Severity: medium
A sophisticated npm supply chain attack was uncovered involving the typosquatted package crypto-javascri, designed to mimic the legitimate crypto-js library. The malware harvests npm and GitHub credentials from infected systems, hijacks maintainer accounts, and automatically repu