
The open-source NPM registry, a cornerstone for countless developers, has once again become a hunting ground for cybercriminals, with the discovery of a sophisticated malicious package designed to systematically plunder sensitive user data. A package named “duer-js,” published by a user called “luizaearlyx,” successfully masqueraded as a benign console visibility tool, tricking developers into incorporating it into their projects. Despite










