#NPM: two hijacked npm packages:
* html-to-gutenberg
* fetch-page-assets
and a cluster of Go packages use VS Code Tasks to deploy #Python Infostealer #malware:
#SoftwareSupplyChainSecurity
👇
https://thehackernews.com/2026/06/hijacked-npm-and-go-packages-use-vs.html
Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer

Researchers found hijacked npm packages and 16 Go packages using fake font files and VS Code tasks to deploy a Python infostealer.

The Hacker News