A "coordinated developer-targeting campaign" is using malicious repositories disguised as legitimate Next.js projects and ...
Attackers used “technical assessment” projects with repeatable naming conventions to blend in cloning and build workflows, ...