Malicious Packages, Hijacked Code, and Phishing: Why Open Source Developers Are Facing a Growing Supply-Chain Nightmare
Image by Kaley Dykstra on Unsplash It’s been a rough week for open source software users—and an even tougher one for developers. Supply-chain attacks are making waves again, this time hitting trusted packages on npm and PyPI that thousands of people rely on. Here’s what went down, and why it should make anyone building with […]