An internal Google memo, first circulated in early April 2026 and since described by multiple people familiar with its ...
Self-propagating npm worm steals tokens via postinstall hooks, impacting six packages and expanding supply chain attacks.