A good reminder to configure strict reject-all DNS email authentication records (SPF, DKIM, DMARC) for domains you won't be sending email from.
NPM emails typically originate from npmjs.COM, which does have these records. But npmjs.ORG, used in this attack, doesn't.
add a skeleton here at some point
4 months ago