Compromised npm and Go Packages Use VS Code Tasks and Blockchain Transactions to Deliver Python Infostealer
JFrog identifies two hijacked npm packages and a cluster of 16 Go packages with a payload that triggers via VS Code's tasks.json and seeks instructions in Tron, Aptos, and BSC transactions.