A weak line of code sat inside one of the most widely used JavaScript cryptography libraries for roughly 12 years before it started stealing money. On August 5, 2026, GitHub published a Critical-severity security advisory for CryptoJS, the npm package that pulls in nearly 9.9 million downloads a week and has shipped inside browser apps…