Incident57 Packages Hijacked Through binding.gyp Files
What Happened Between late 2024 and early 2025, attackers compromised 57 npm packages using a technique that bypasses common security controls. Instead of hiding code in lifecycle scripts like preinst














