Public packages get priority over private packages with the same name. You can see where this is going...
Major companies including Microsoft, Apple, PayPal, Shopify, Netflix, Yelp, Tesla, and Uber compromised in a novel software supply chain attack.
Malware was placed in open source repositories, which then got distributed downstream into the applications:
bleepingcomputer.com/news/se…
Feb 10, 2021 · 12:07 PM UTC
1
