When the ua-parser-js maintainer's npm token was stolen in October 2021, the poisoned release sat live for about four hours. npm audit reported zero vulnerabilities during those four hours, for a package with 7 million weekly downloads. If your incident plan starts with "run the scanner," you d...

Source: [Dev.to](https://dev.to/secbyjasonmiller/npm-audit-wont-save-you-in-the-first-hour-of-a-supply-chain-alert-h79)

Sponsored