security1 distinct publisher
WSL is a working bridge, and npm hygiene stops at the container wall
CloudSEK's BRIDGEHEAD report tracks forty npm typosquats whose install script tests for Windows underneath Linux, then pulls a Rust stealer that reads the host's wallets and cookies.
Publishers:cloudsek.com
Reality
- Evidence63
- Adoption27