|
|
|
|
|
by SahAssar
1693 days ago
|
|
The most common ways these things seem to happen is either password reuse with no 2fa or that the npm token (in ~/.npmrc) was harvested by another compromised package/program. IIRC there were a few that were due to phishing too. |
|