The npm Supply Chain Worm That Just Hit 2 Billion Downloads: What Every Dev Team Needs to Do Now
A self-propagating worm compromised npm packages with over 2 billion monthly downloads via a single hijacked maintainer account. Here’s how it spread and how to limit your exposure.