Open-Source Info Stealer RAT Hides in Malicious npm Packages

ICYMI: TurkoRat Capable of Credential Harvesting, Contains Features Such as Wallet Grabber
Researchers have identified two legitimate-looking malicious npm packages that concealed an open-source info stealer for two months before being detected and removed. Developers downloaded the TurkoRat malware about 1,200 times from open-source repositories.
http://dlvr.it/SpTtFF