Mastra npm packages added easy-day-js malware, exposing developer systems and CI runners to infostealer risks.
The free platform, called Journal Trends, could also allow integrity sleuths to spot low-quality publications.
GitHub has announced that npm v12, expected next month, will introduce several security-focused changes aimed at blocking ...