The Worm That Keeps on Digging: Latest Wave

Reported 19 May 2026 by otx · Severity: medium

A sophisticated supply chain campaign targeting the open source developer ecosystem has emerged, compromising NPM packages in the @antv namespace, GitHub Actions including actions-cool/issues-helper, and the VSCode extension nrwl.angular-console. The malware initiates multi-stage