JFrog found malicious npm packages that deploy a Windows RAT to steal Chrome credentials, run commands, and transfer files.
The editor knows to read it. An AI agent reading the raw JSON doesn't. So when a founder hands that JSON to an agent and asks it to rebuild the app in code, the agent reads 50 user fields and rebuilds ...