Simple supply chain attack compromises hundreds of websites and apps

A simple NPM supply-chain attack has led to the compromise of thousands of websites and desktop apps, researchers have found. 

According to ReversingLabs, a threat actor known as IconBurst has created a number of malicious NPM modules capable of exfiltrating serialized form data, and given them names almost identical to other, legitimate modules.

Source