A critical flaw in a WordPress add-on was recently patched, which allows crooks to add a rogue admin account to the site.
Researchers found a fake Ethereum helper package on crates.io that secretly downloaded OS-specific payloads and executed them on developer machines.