npm
230 articles with this tag
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
MEDIUM
HIGH
HIGH
CRITICAL
MEDIUM
MEDIUM
MEDIUM
MEDIUM
MEDIUM
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
MEDIUM
HIGH
HIGH
MEDIUM
INFO
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
MEDIUM
HIGH
CRITICAL
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
INFO
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
CRITICAL
HIGH
LOW
HIGH
MEDIUM
Coding Agent Horror Stories: The 29 Million Secret Problem
GitHub delays version updates so malware gets caught first
New npm malware cluster targets Vite ecosystem
Sequel to ChainVeil npm Malware Targets Vite Ecosystem
Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery
NPM ecosystem hit with two new supply chain compromises
Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware
Multiple Jscrambler Packages Impacted by Supply Chain Attack
Jscrambler npm package version 8.14.0 contained a malicious infostealer
Injective Labs SDK npm package compromised to steal cryptocurrency keys
npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk
Miasma campaign poisons 20-plus npm packages, hunts for developer secrets
From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet
TanStack npm compromise: 42 packages published with valid SLSA provenance via OIDC token theft from runner memory
What the Miasma campaign reveals about the new supply chain threat model and the underground market for developer credentials
North Korean Hackers Blamed for Mastra NPM Supply Chain Attack
From package to postinstall payload: Inside the Mastra npm supply chain compromise
Mastra npm packages compromised in 'easy-day-js' supply chain attack
A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope
144 Mastra npm Packages Compromised via Hijacked Contributor Account
Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign
NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks
The Axios npm compromise was visible in registry metadata before anyone ran npm install
Malicious npm packages abuse dependency confusion to profile developer environments
GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks
GitHub finally pulls the plug on automatic install script execution for npm
NPM v12 to block supply-chain attacks with new security measures
GitHub announces npm security changes to tackle supply-chain attacks
GitHub pulls pin on npm's auto-run scripts
Lazarus Group's Latest: Brandjacking Campaign on npm
IronWorm malware, similar to Shai-Hulud, hits 57 projects across 9 organizations
IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks
Rust-Written IronWorm Hits NPM Supply Chain
New IronWorm malware hits 36 packages in npm supply-chain attack
Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp
Typosquatted npm packages used to steal cloud and CI/CD secrets
Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign
Why supply chain attacks work and what detection can actually do about it
Four coordinated npm supply chain campaigns active in May–June 2026 — TTPs, IOCs, and detection notes
Famous Chollima Targets PHP Developers Through Compromised Packagist Package
Infected Red Hat npm packages expose developer credentials
Supply Chain Attack Hits 32 Red Hat NPM Packages
Attack targeting OpenAI Codex users exposes AI software supply chain risks
Red Hat npm packages compromised in new Mini Shai-Hulud malware wave
Attackers Hijack Red Hat npm Scope to Steal Cloud Secrets
Miasma supply chain attack: malicious code found in @redhat-cloud-services npm packages
Dozens of Red Hat packages backdoored through its offical NPM channel
OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack
Lone attacker published 14 malicious npm packages mimicking popular OpenSearch, Elasticsearch libraries
A practical checklist for evaluating npm packages (supply chain attacks, slopsquatting, etc.)
Typosquatted npm packages used to steal cloud and CI/CD secrets
Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft
Download pumping: New npm deception technique for supply chain attacks
Well-architected best practices for software supply chain security
TrapDoor malware campaign puts developer workstations in CISO spotlight
npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks
Mini Shai-Hulud: Frequently asked questions about the TeamPCP npm and PyPI supply chain campaign
Grafana Labs Says Code Breach Stemmed from TanStack Attack
GitHub links repo breach to TanStack npm supply-chain attack
New Mini Shai-Hulud attack targets npm ecosystem
Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft
Mini Shai-Hulud Hits Hundreds of npm Packages in AntV Ecosystem
Over 320 NPM Packages Hit by Fresh Mini Shai-Hulud Supply Chain Attack
AntV data visualization tool the latest to be hit by ongoing npm supply chain attacks
New Shai-Hulud malware wave compromises 600 npm packages
Mini Shai-Hulud Hits AntV: 300+ Malicious npm Packages Published via Compromised Maintainer Account
Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account
Leaked Shai-Hulud malware fuels new npm infostealer campaign
TanStack Supply Chain Attack (And How to Lock Down GitHub Actions)
First Shai-Hulud Worm Clones Emerge
Cisco, Canvas, Microsoft, Exchange 0-Days, NPM Backdoors, GPT-5.5 and more... - SWN #581
Expired domain leads to supply chain attack on node-ipc npm package
Popular node-ipc npm package compromised to steal credentials
Malicious node-ipc versions published to npm in suspected maintainer account compromise
OpenAI caught in TanStack npm supply chain chaos after employee devices compromised
Stealer Backdoor Found in 3 Node-IPC Versions Targeting Developer Secrets
Axios breach shows why software supply chains need zero trust
Hunting the Behavior Behind npm Supply Chain Attacks
Trusted by default: The npm attack pattern security teams miss
‘Mini’ Shai-Hulud attack compromises hundreds of npm, PyPI packages
Mini Shai-Hulud Hits TanStack npm Packages
Cache-poisoning caper turns TanStack npm packages toxic
Shai Hulud attack ships signed malicious TanStack, Mistral npm packages
TanStack, Mistral AI, UiPath Hit in Fresh Supply Chain Attack
Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages
TanStack Npm Packages Compromised Inside The Mini Shai Hulud Supply Chain Attack
Cline Kanban Flaw Lets Websites Hijack AI Coding Agents
Illicit AI-assisted commit-linked npm dependency compromises crypto wallets
Supply chain attack against SAP npm packages facilitates credential theft
1,800 Hit in Mini Shai-Hulud Attack on SAP, Lightning, Intercom
Why You Must Check Your Password Manager Immediately | THREAT WIRE
The never-ending supply chain attacks worm into SAP npm packages, other dev tools
SAP NPM Packages Targeted in Supply Chain Attack
'Mini Shai-Hulud' supply chain attack targets SAP npm packages
A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages
SAP npm Packages Compromised by “Mini Shai-Hulud” Credential-Stealing Malware
Malicious npm Dependency Linked to AI Assisted Commit Targets Crypto Wallets
Set up automated dependency scanning after the recent npm/PyPI supply chain attacks
Tradecraft Tuesday Recap: axios npm Supply Chain Compromise
STARDUST CHOLLIMA Likely Compromises Axios npm Package