The link you clicked points at a different website. We do not run that site and we cannot promise anything about what is on it. If you still want to go there, the button below opens it in a new tab.

A malicious npm package hit 2 million weekly downloads without a single install script. Checkmarx Zero found it hides in the code itself and uses a smart contract as its C2 channel — a live look at how npm's lifecycle-script crackdown just pushed attackers one step further.
If the address looks unfamiliar, close this tab and use the navigation above instead. TorPortal does not endorse third party sites and links inside news stories come straight from the source article.