Example copy of one of the inserted JS: https://pastebin.com/bwLZrq02
Derek's caught it too https://infosec.exchange/@derekheld/115169311485030806
It's a cryptocurrency wallet drainer, RIP a load of devops dudes crypto.
NPM on it, some packages nuked, more being nuked
Weekly download stats for impacted packages prior to incident
ansi-styles (371.41m)
debug (357.6m)
backslash (0.26m)
chalk-template (3.9m)
supports-hyperlinks (19.2m)
has-ansi (12.1m)
simple-swizzle (26.26m)
color-string (27.48m)
error-ex (47.17m)
color-name (191.71m)
is-arrayish (73.8m)
slice-ansi (59.8m)
color-convert (193.5m)
wrap-ansi (197.99m)
ansi-regex (243.64m)
supports-color (287.1m)
strip-ansi (261.17m)
chalk (299.99m)
Total 2674m
Phishing email sent to maintainers, they basically targeted people with 2FA by getting them to.. reset their 2FA.
@GossiTheDog Fortunately, no one that is writing code for industrial control systems are using those poorly understood libraries..... RIGHT???