#8
Open source package with 1 million monthly downloads stole user credentials
An open-source package downloaded a million times per month was caught stealing user credentials, a stark reminder that trust in shared code is a fragile, dangerous gift. The package, a popular npm utility, exfiltrated login data via a hidden HTTPS connection, harvesting 1.2 million tokens over six months before discovery. The incident led to a 40% drop in the package's downloads within 24 hours.
Photos (1)

Comments on "Open source package with 1 million monthly downloads stole user credentials"
Have a take on this ranking?
Comments are how the argument actually happens here. Posting one needs a free account — it takes about a minute.
No comments yet.
The first comment sets the terms of the argument.