Incidentnpm Postinstall Hook Exfiltrated Keyboard Shortcuts
What Happened A security researcher demonstrated that npm s default configuration allows malicious packages to exfiltrate macOS keyboard shortcuts through Node.js scripts executed during package insta














