It was a rough week for the software supply chain. 32 malicious @redhat-cloud-services npm packages shipped credential-stealing malware via a preinstall hook, and Mitiga Labs found spyware, hijacked ...