A critical improper input validation vulnerability in the npm component netmasks component has been lurking in a popular npm component. The flaw concerns the netmask component that gets over 3 million weekly downloads on npm, and is a dependency for almost 280,000 GitHub repositories. The exact scope of risk resulting from exploitation of such a flaw remains wide, comprising many possibilities. PHP’s Git server was hacked in a sophisticated supply chain attack this week. This is the same news as the PHP powers almost 8 out of 10 websites on the internet.”]

