#OpenSource Poisoned #Patches Infect Local #Software. Malicious packages lurking on open source repositories like #npm have become less effective, so cyberattackers are using a new strategy: offering "patches" for locally installed programs.
https://www.darkreading.com/cloud-security/open-source-poisoned-patches-infect-local-software