Socket found a malicious postinstall hook across 700+ GitHub repos, including #PHP packages on Packagist and #Nodejs project repos.
The campaign involved malicious commits to affected repositories and reused the same GitHub-hosted payload infrastructure.
https://t.co/qC8ykZxxno