The fact
This discovery alerts the open-source community to risks of software supply chain compromise through popular repositories.
Developers are urged to audit their dependencies and strengthen verification mechanisms for third-party packages.
Click the link to read an article on the topic: