- 8th September 2025
A forged 2FA email led to malicious npm releases of chalk, debug, ansi-* and more. The payload targets browser crypto flows, rewriting wallet destinations. Use our repo scanner to spot the exact bad versions and IOC URLs, then shift to ownership-driven ASPM to cut MTTR and SLA breaches.
Francesco Cipollone