Security researchers from ReversingLabs have uncovered a series of high-profile compromises targeting popular open-source packages, highlighting the growing risk of malicious code infiltration in widely-used software tools. The researchers discovered cryptomining malware had been injected into packages associated with rspack and vant. The compromises of these frequently downloaded tools were made possible using stolen npm tokens.

Security leaders overconfident about ransomware recovery
Few manage to recover all their data, and many experience business disruption


