/
Someone hid a full RAT inside a fake npm package and exfiltrated victim data to HuggingFace — Trendlair