Original caption
This malware can never be taken down. A contributor tried to smuggle malicious code into Better-Auth, a popular open source JS library, through a legitimate-looking pull request. Once the merged code runs, it pulls its real payload from blockchain transactions. Unlike the Axios attack on GitHub, you can't file a takedown request against a blockchain. It's globally replicated across thousands of independent nodes and designed to be immutable. Watch the full breakdown at the link in bio. #cybersecurity #appsec #opensource #supplychainsecurity