JFrog says six malicious npm packages used hidden install-time execution, JSONKeeper fetches, and sandbox checks to enable remote access.
The very first one, for example, has three people on the map, one marked with a C (the target customer) and two marked with ...