Two malicious npm packages, express-api-sync and system-health-sync-api, have been discovered, posing a significant threat to production systems. Published under the npm alias “botsailer,” the packages install backdoors capable of deleting all files within an application. Unlike typical malware, these tools prioritise data destruction over theft, highlighting a growth in software supply chain threats. Socket’s Threat Research Team urges developers to use behavioural scanning tools to detect such threats.

The True Cost of Focusing on Cost Instead of Cost-Effectiveness
When payors consider only the cost of the medication and not the cost and risk to the patient, doctor, and healthcare system, the irony is


