The campaign spans npm, Packagist, Go, and Chrome, using obfuscated JavaScript loaders and VS Code tasks to deliver malware.
Journalists can only report what they can verify and they are ethically required to offer right of reply to story subjects ...