Clever Use of QR Codes Sparks Security Concerns in npm Packages
The Socket Threat Research Team recently uncovered an intricate scheme embedded within a seemingly benign npm package, fezbox. This package, masquerading as a high-performance JavaScript/TypeScript utility, includes modules for standard helper functions and QR code manipulation. However, beneath