Collector
Another npm supply chain worm is tearing through dev environments | Collector
Another npm supply chain worm is tearing through dev environments
The Register

Another npm supply chain worm is tearing through dev environments

Plus, the payload references 'TeamPCP/LiteLLM method' Yet another npm supply-chain attack is worming its way through compromised packages, stealing secrets and sensitive data as it moves through developers' environments, and it shares significant overlap with the open source infections attributed to TeamPCP last month.…

Go to News Site