·VentureBeat
Valid certificates, stolen accounts: how attackers broke npm's last trust signal
On May 19, attackers published 633 malicious npm package versions that passed Sigstore provenance checks because the signing certificates were generated from compromised maintainer...

read →
