The "Yeshen-Asia" campaign, a sprawling six-month operation attributed to a suspected Chinese threat actor, involved over 60 malicious npm packages.
July 8, 2025
Get the latest cybersecurity stats delivered to your inbox every week
Browse more stats from Sonatype or explore Open source
Join 1,000+ security professionals getting weekly insights