Spotify confirmed the incident and says it has disabled user accounts linked to it, but that won’t un-leak the music.
A malicious package in the Node Package Manager (NPM) registry poses as a legitimate WhatsApp Web API library to steal ...