Two malicious npm packages, express-api-sync and system-health-sync-api, have been discovered, posing a significant threat to production systems. Published under the npm alias “botsailer,” the packages install backdoors capable of deleting all files within an application. Unlike typical malware, these tools prioritise data destruction over theft, highlighting a growth in software supply chain threats. Socket’s Threat Research Team urges developers to use behavioural scanning tools to detect such threats.

In the Age of AI, Interoperability Isn’t Enough: Why Healthcare Needs Shared Understanding, Not Just Shared Data
The industry needs a framework that can translate clinical nuance into a consistent, trusted representation across systems and use cases. The post In the Age


