pull down to refresh
https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised
from @evankaloudis
The code first checks for the existence of window.ethereum, an object injected by wallet extensions like MetaMask. If no wallet is found, it proceeds with a passive attack.
Hmm...yes I forgot about MetaMask....thats probably the intended target.
https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised
from @evankaloudis