JFrog says six malicious npm packages used hidden install-time execution, JSONKeeper fetches, and sandbox checks to enable remote access.
If you're considering PuppeteerSharp for PDF generation, here's the version of the story that doesn't show up in the "getting started" docs.
WASM OJ Wonderland: A SvelteKit-based online judge system core. PEA: A serverless email authentication and verification service. Add your project here by submitting a pull request!