npm
206 articles with this tag
MEDIUM
MEDIUM
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
MEDIUM
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
HIGH
CRITICAL
LOW
CRITICAL
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
MEDIUM
HIGH
HIGH
CRITICAL
MEDIUM
MEDIUM
MEDIUM
MEDIUM
MEDIUM
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
MEDIUM
HIGH
HIGH
MEDIUM
INFO
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
MEDIUM
HIGH
CRITICAL
HIGH
HIGH
Shai-Hulud npm worm resurfaces, bypassing security scans
[UPDATE] [niedrig] npm: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
Prompting the Payload: How an npm Supply Chain Attack Delivers the RedC2 AI-Powered Linux Implant
24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages
Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
Inside the fourth wave of the Shai-Hulud npm worm
ChainDrop worm crawls into npm supply chain, evades standard defenses
Six npm Packages Use Ethereum Transactions to Retrieve Malicious Payloads
ChainDrop supply chain compromise: Anatomy of a self-propagating worm
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
ChainDrop: Inside a Self-Propagating npm Worm
North Korea linked to new NullReceiver C2 technique
Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages
Trojanized npm Packages Decode C2 IP From Ethereum Recipient Addresses
Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack
ChainDrop supply chain compromise: Anatomy of a self-propagating worm
ChainDrop credential stealing worm infects over 400 npm packages
Keyv, cacheable npm supply chain attack hits 400-plus packages
Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks
Uptime Kuma 2.5.0 waits two weeks before trusting a new npm package
18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
Amazon attributes axios, debug, chalk NPM attacks to DPRK’s Sapphire Sleet
Amazon identifies North Korean hacker group behind open-source supply chain attacks
A little-known npm package was North Korea’s warm-up act for the axios hack
Secure your npm and pip package updates in Amazon Linux
Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery
Coding Agent Horror Stories: The 29 Million Secret Problem
GitHub delays version updates so malware gets caught first
New npm malware cluster targets Vite ecosystem
Sequel to ChainVeil npm Malware Targets Vite Ecosystem
Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery
NPM ecosystem hit with two new supply chain compromises
Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware
Multiple Jscrambler Packages Impacted by Supply Chain Attack
Jscrambler npm package version 8.14.0 contained a malicious infostealer
Injective Labs SDK npm package compromised to steal cryptocurrency keys
npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk
Miasma campaign poisons 20-plus npm packages, hunts for developer secrets
From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet
TanStack npm compromise: 42 packages published with valid SLSA provenance via OIDC token theft from runner memory
What the Miasma campaign reveals about the new supply chain threat model and the underground market for developer credentials
North Korean Hackers Blamed for Mastra NPM Supply Chain Attack
From package to postinstall payload: Inside the Mastra npm supply chain compromise
Mastra npm packages compromised in 'easy-day-js' supply chain attack
A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope
144 Mastra npm Packages Compromised via Hijacked Contributor Account
Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign
NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks
The Axios npm compromise was visible in registry metadata before anyone ran npm install
Malicious npm packages abuse dependency confusion to profile developer environments
GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks
GitHub finally pulls the plug on automatic install script execution for npm
NPM v12 to block supply-chain attacks with new security measures
GitHub announces npm security changes to tackle supply-chain attacks
GitHub pulls pin on npm's auto-run scripts
Lazarus Group's Latest: Brandjacking Campaign on npm
IronWorm malware, similar to Shai-Hulud, hits 57 projects across 9 organizations
IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks
Rust-Written IronWorm Hits NPM Supply Chain
New IronWorm malware hits 36 packages in npm supply-chain attack
Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp
Typosquatted npm packages used to steal cloud and CI/CD secrets
Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign
Why supply chain attacks work and what detection can actually do about it
Four coordinated npm supply chain campaigns active in May–June 2026 — TTPs, IOCs, and detection notes
Famous Chollima Targets PHP Developers Through Compromised Packagist Package
Infected Red Hat npm packages expose developer credentials
Supply Chain Attack Hits 32 Red Hat NPM Packages
Attack targeting OpenAI Codex users exposes AI software supply chain risks
Red Hat npm packages compromised in new Mini Shai-Hulud malware wave
Attackers Hijack Red Hat npm Scope to Steal Cloud Secrets
Miasma supply chain attack: malicious code found in @redhat-cloud-services npm packages
Dozens of Red Hat packages backdoored through its offical NPM channel
OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack
Lone attacker published 14 malicious npm packages mimicking popular OpenSearch, Elasticsearch libraries
A practical checklist for evaluating npm packages (supply chain attacks, slopsquatting, etc.)
Typosquatted npm packages used to steal cloud and CI/CD secrets
Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft
Download pumping: New npm deception technique for supply chain attacks
Well-architected best practices for software supply chain security
TrapDoor malware campaign puts developer workstations in CISO spotlight
npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks
Mini Shai-Hulud: Frequently asked questions about the TeamPCP npm and PyPI supply chain campaign
Grafana Labs Says Code Breach Stemmed from TanStack Attack
GitHub links repo breach to TanStack npm supply-chain attack
New Mini Shai-Hulud attack targets npm ecosystem
Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft
Mini Shai-Hulud Hits Hundreds of npm Packages in AntV Ecosystem
Over 320 NPM Packages Hit by Fresh Mini Shai-Hulud Supply Chain Attack
AntV data visualization tool the latest to be hit by ongoing npm supply chain attacks
New Shai-Hulud malware wave compromises 600 npm packages
Mini Shai-Hulud Hits AntV: 300+ Malicious npm Packages Published via Compromised Maintainer Account
Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account
Leaked Shai-Hulud malware fuels new npm infostealer campaign
TanStack Supply Chain Attack (And How to Lock Down GitHub Actions)
First Shai-Hulud Worm Clones Emerge
Cisco, Canvas, Microsoft, Exchange 0-Days, NPM Backdoors, GPT-5.5 and more... - SWN #581
Expired domain leads to supply chain attack on node-ipc npm package
Popular node-ipc npm package compromised to steal credentials