Insights into how maintainers of popular libraries are being targeted:
https://socket.dev/blog/attackers-hunting-high-impact-nodejs-maintainers

#security

Attackers Are Hunting High-Impact Node.js Maintainers in a C...

Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Socket