The maintainer of one of our dependencies, debug, was the target of a phishing attack resulting in the release of debug@4.4.2 with malware. Supply chain security is all of our responsibilities. Be careful out there, and for today don't update your deps. socket.dev/blog/npm-aut...
npm Author Qix Compromised via Phishing Email in Major Suppl...
npm author Qix’s account was compromised, with malicious versions of popular packages like chalk-template, color-convert, and strip-ansi published.
socket.dev