Researchers outline how the PhantomRaven campaign exploits hole in npm to enable software supply chain attacks.
It allows any Chromium browser to collapse in 15-60 seconds by exploiting an architectural flaw in how certain DOM operations ...