Attackers invite targets to collaborate on a project, convincing them to download and run a repository with malicious npm dependencies.

https://lemmy.world/post/1731808

Attackers invite targets to collaborate on a project, convincing them to download and run a repository with malicious npm dependencies. - Lemmy.world

Man that’s clever