The security tool your developer just installed may have already stolen your cloud keys.

The security tool your developer just installed may have already stolen your cloud keys. Red Hat’s official npm namespace was compromised on June 1. Thirty-two packages under @redhat-cloud-services — collectively downloaded ~80,000 times per week — contained a preinstall script that ran before a single line of application code executed. By the time the package…

Read More