Twenty-four malicious npm packages have been used to turn trusted package mirrors into staging points for ClickFix phishing ...
A critical isolated-vm flaw lets untrusted JavaScript escape the V8 sandbox and potentially hijack the host process.