Socket<p>🚨 We uncovered a malware campaign on npm targeting devs using <a href="https://fosstodon.org/tags/React" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>React</span></a>, <a href="https://fosstodon.org/tags/Vue" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Vue</span></a>, <a href="https://fosstodon.org/tags/Vite" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Vite</span></a>, <a href="https://fosstodon.org/tags/Nodejs" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Nodejs</span></a> & the Quill rich text editor. </p><p>These destructive packages delete files, crash systems, and break apps in subtle, chaotic ways. Full report → </p><p><a href="https://socket.dev/blog/malicious-npm-packages-target-react-vue-and-vite-ecosystems-with-destructive-payloads" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">socket.dev/blog/malicious-npm-</span><span class="invisible">packages-target-react-vue-and-vite-ecosystems-with-destructive-payloads</span></a> <a href="https://fosstodon.org/tags/JavaScript" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>JavaScript</span></a> <a href="https://fosstodon.org/tags/infosec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>infosec</span></a></p>