Critical Supply Chain Breach: Popular 'debug' npm Package Compromised with Cryptominer Payload
A malicious version (4.4.2) of the ubiquitous JavaScript debugging library 'debug' was published to npm, containing cryptomining malware that targets browser environments. With over 11 million weekly downloads, this supply chain attack poses significant risks to countless Node.js and web applications.