If you were holding off from that AliExpress purchase, here's some news you might be interested in ...
Hulud payload to steal CI/CD secrets from Linux-based automation environments. The malware executes during npm install and ...