Malware planted during a bogus coding assessment harvested a session token, bypassing multi-factor authentication to reach a code repository.

Read Full Story at Decrypt.co →