Researchers say the campaign targeted developer credentials and cloud secrets while abusing trusted publishing and AI coding ...
Malicious code inserted into four SAP-related npm packages exposed developer workstations and automated build systems to credential theft, marking a sharp escalation in attacks against open-source ...