Post cover image

May 30, 2026

A worm shipped to npm with a valid signature, and I rotated tokens till 2am

I found out from a Slack bot. 11-something on a Tuesday night, I’m half-watching something and not really watching it, and our security…

The Expert Developer

4 min read