Cyb3rius
@cyb3rius
· Aug 5
In early 2025, attackers hijacked the popular 'image-size' npm library, slipping in a backdoor that stole auth tokens from major orgs. The supply-chain attack went unnoticed for months, underscoring how overlooked dependencies can quietly compromise entire ecosystems.
0