A malicious campaign has been planting info-stealing packages on open-source platforms, with about 75,000 downloads so far. The campaign has evolved to include more sophisticated obfuscation techniques, and the malware can steal sensitive data and manipulate app data.
















