Cyber CrimeNewProvenance Fails as npm Supply Chain Attack HitsCloudSEK reports attackers abused npm trusted publishing to ship GHAPPIER loader, exposing limits of provenance attestations.3 hours ago