Technology ❯ Software Development ❯ Open Source Software ❯ Package Management
Stolen GitHub credentials let poisoned releases run a Bun‑launched infostealer that harvests developer and cloud secrets, repackages them, and propagates through npm.