Attackers invite targets to collaborate on a project, convincing them to download and run a repository with malicious npm dependencies.
Attackers invite targets to collaborate on a project, convincing them to download and run a repository with malicious npm dependencies.

Security alert: social engineering campaign targets technology industry employees - The GitHub Blog

Man that’s clever