A malicious JavaScript package was uploaded Dec. 30 2019 on the Node Package Manager (npm), the worlds largest software registry, containing over 800,000 code packages. The package, identified as 1337qq-js, was spotted stealing sensitive data through install scrips of Unix Systems. The data it collects includes running processes, environment variables, uname a, npmrc file and /etc/hosts. It marks the sixth-known incident to strike the npm repository in the past three years.”]

