That npm Malware Downloaded 17,000 Times? It Tried to Gaslight AI
A malicious npm package tried to manipulate AI security scanners with a hidden prompt. Despite being flagged months ago, it remained downloadable and was installed nearly 17,000 times. This shows a dangerous gap between detection and actual removal in the software supply chain.