According to Koi Security, a legitimate-looking developer managed to slip in rogue code within an npm package called " ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible resultsSome results have been hidden because they may be inaccessible to you
Show inaccessible results