What's Inside?
- • Install chain attacks that execute during
npm install - • Credential harvesting, token exfiltration, and secrets scraping
- • C2 beacons (Discord, Telegram), obfuscation, persistence tricks
- • Package scores and severity rollups with per-rule context