🚨 New Investigation: Attackers are hunting the maintainers behind Lodash, Fastify, buffer, Pino, mocha, Express, and #Nodejs core, because compromising one of them means write access to packages downloaded billions of times a week.

Multiple high-impact maintainers have all confirmed they were targeted in the same coordinated social engineering campaign that compromised Axios.

https://socket.dev/blog/attackers-hunting-high-impact-nodejs-maintainers

Attackers Are Hunting High-Impact Node.js Maintainers in a C...

Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Socket
@SocketSecurity Ohhhhh, that was it! I was targeted as well (probably for hapi and/or joi), found it quite rude to recruit like that, so I didn't even bother 😂 Thanks for the investigation, that's super helpful as always 🙏
@marsup Glad you weren't snared by it! Stay safe!