A new npm supply-chain incident involving packages under Red Hat's @redhat-cloud-services namespace has once again highlighted how attractive developer ecosystems have become to attackers. Instead of going directly after end users, modern threat actors are increasingly targeting the tools, libraries and publishing pipelines that developers trust every day.

