Top npm package backdoored to drop dirty RAT on dev machines
… Google’s Threat Intelligence Group GTIG on Tuesday linked the axios NPM supply chain attack to a suspected North Korean threat actor it tracks as UNC1069 - and not to TeamPCP, the group behind the recent Trivy vulnerability scanner breach and subsequent compromises targeting other popular open sour… …