Nothing is safe. A few days ago, Phylum's automated platform identified a malicious package targeting users of the #gulp toolkit. The package drops a remote access tool and other nastiness.
https://blog.phylum.io/sophisticated-rat-shell-targeting-gulp-projects-on-npm
#javascript #malware #npm #typescript #opensource #gulpjs #software #programming