NPM package ‘is' with 2.8M weekly downloads infected devs with malware
From BleepingComputer to All on Wed Jul 23 12:54:56 2025
The popular NPM package 'is' has been compromised in a supply chain attack that injected backdoor malware, giving attackers full access to compromised devices. [...]