LiquidJS RCE, a Trojanized npm Package, and GitHub Copilot's Billing Overhaul
This week delivered a brutal reminder that the software supply chain is under siege from every angle — while the AI tools meant to protect and empower developers are simultaneously becoming more powerful and more dangerous to use carelessly.
A maximum-severity remote code execution vulnerability in a JavaScript template engine with