A Self-Propagating npm Worm Is Actively Spreading Through Developer Environments

OAuth Redirect Abuse Lets Attackers Bypass MFA Without Stealing Tokens

Developer-targeting campaign using malicious Next.js repositories