34 Malicious Packages, 23 States, Zero Encryption: Supply-Chain Rot Hits US Small Businesses
🎉 Your Router Is a Sieve, and You're Paying for the Colander
34+ malicious packages dropped into npm, PyPI, and Crates.io — eth-security-auditor, prompt-engineering-toolkit — credential-theft payloads infecting developer toolchains across 23 US states. 🎉 That's the TrapDoor supply-chain campaign, hitting the exact