Unfortunately, we're once again on campaign to mitigate supply chain attacks. You're not immune to them, so stay aware and follow the tips in this guide to protect your projects.
Popular npm packages keyv and cacheable were hijacked, and malicious versions containing a malware were released to steal users’ access tokens. Protect your packages from the same fate with my guide, based on maintaining PostCSS and 100+ other projects: evilmartians.com/chronicles/t...