Attackers increasingly are using malicious JavaScript packages to steal data, engage in cryptojacking and unleash botnets, offering a wide supply-chain attack surface for threat actors.
https://threatpost.com/malicious-npm-packages-web-apps/178137/
Joker malware was found lurking in the Color Message app, ready to fleece unsuspecting users with premium SMS charges.
https://threatpost.com/malicious-joker-app-downloads-google-play/177139/