A social-engineering attack on a maintainer led to malicious versions that stole private keys and drained wallets.
The official Solana JavaScript SDK; malicious versions were live for ~5 hours with wide reach.
A legitimate package's maintainer account or pipeline was taken over and a malicious version published.
Attacks like this are why dependency provenance matters. Scan your manifests against the Gold database, or add the free CI gate to block risky dependencies before they merge.