A malicious package in the Node Package Manager (NPM) registry poses as a legitimate WhatsApp Web API library to steal ...
The letter looked innocent at first glance, but actually contained a secret code ordering a hit on a jail staff member.