npm supply chain: valid certificates, stolen accounts

TL;DR AI
2 min readKey summary
Attackers abused compromised maintainer accounts and stolen credentials to publish signed malicious npm packages and a compromised VS Code extension.
The incidents show that provenance and signatures can verify how code was built, but not whether the publisher was truly authorized.
Researchers also found broader risks in AI coding tools and MCP workflows, including prompt injection, auto-execution, and unsafe automation.
The result is a supply-chain blind spot that can spread malicious code quickly across registries, IDEs, and developer assistants.
