Two npm Packages Compromised via Stolen Credentials15. July 2026CybersecurityAttackers exploited a GitHub Actions vulnerability to steal developer tokens and poison ten npm packages with modular malware. Share on: