binding.gyp Is the npm Attack Vector You Forgot to Audit
The Miasma worm hit 32 @redhat-cloud-services packages by hiding code execution in binding.gyp, not package.json scripts. If your scanner only audits install hooks, you have a hole.
/Blog
Content about design, technology, and the weird stuff in between.