
Typosquatt alert ! Malicious npm Package: nyc-config
Possible typosquatting against @istanbuljs/load-nyc-config with ~25M weekly downloads.

Possible typosquatting against @istanbuljs/load-nyc-config with ~25M weekly downloads.

Multiple npm packages impersonating popular package names are being used to distribute malware. We take a closer look at the campaign.

Multiple npm packages impersonating popular package names were published to the npm registry including by a Snyk researcher apparently targeting internal packages at Cursor AI.
