A newly discovered malicious npm package has compromised thousands of developer environments after masquerading as a legitimate JavaScript dependency. The package, named “ambar-src,” appeared harmless at first and gained widespread trust before attackers activated a hidden payload. Once deployed, the malware granted full system access to threat actors. The incident highlights ongoing weaknesses in the…