| I wonder who actually discovered this attack? Can we credit them? The phrasing in these posts is interesting, with some taking direct credit and others just acknowledging the incident. Aikido says:
> We were alerted to a large-scale attack against npm... Socket says:
> Socket.dev found compromised various CrowdStrike npm packages... Ox says:
> Attackers slipped malicious code into new releases... Safety says:
> The Safety research team has identified an attack on the NPM ecosystem... Phoenix says:
> Another supply chain and NPM maintainer compromised... Semgrep says:
> We are aware of a number of compromised npm packages |