Npm team warns of new 'binary planting' bug Npm bug lets booby-trapped npm (JavaScript) packages plant or alter binaries on the victim's system December 13, 2019 https://www.zdnet.com/article/npm-team-warns-of-new-binary-planting-bug/ An in-depth technical report: binary planting and arbitrary file (over)write vulnerabilities in npm, pnpm and yarn