
🚨 A widely used npm package was compromised.
STARDUST CHOLLIMA likely targeted Axios using stolen credentials, deploying new cross-platform ZshBucket variants.
This is supply chain risk at scale.
Read the full breakdown: crwdstr.ke/6010BBbw8A

English

