NPM debug and chalk packages compromised - Anatomy of a Billion-Download NPM Supply-Chain Attack
The NPM account of the popular developer qix was compromised, leading to malicious versions being published for dozens of packages, including chalk, strip-ansi, and color-convert.
2025. 09. 09.