Australian authorities have charged two alleged TeamPCP members after software supply chain attacks exposed over 500,000 credentials and at least 300GB of data.
Shai-Hulud npm worm spreads through Keyv and hundreds of packages with 2 billion monthly downloads, stealing npm, GitHub, cloud and CI credentials in real time.