Browsing: npm
Attackers planted an infostealer inside 36 npm packages linked to the Arweave ecosystem. It targeted developer credentials, SSH keys, and…
npm Finally Intervenes in ‘Mini Shai-Hulud’ Crisis, but Crypto Security Experts Call It Half-Measure
After a prolonged silence, the npm registry administration finally stepped into the situation surrounding the massive supply-chain attack and urgently…
Key TakeawaysMini Shai-Hulud exploited GitHub Actions on May 19, compromising 300+ npm packages across 16M weekly downloads.The malware installs a…
Four npm packages that were connected to SAP’s Cloud Application Programming Model were stolen. The hackers added code that steals…
A malicious npm dependency linked to an AI-assisted code commit has been found stealing sensitive data and exposing crypto wallets.…
Malicious npm packages have been identified distributing malware that steals credentials and attempts to spread across developer ecosystems. According to…
Ethereum and Solana developers were targeted by five malicious npm packages that steal private keys and send them to the…
A new malicious npm campaign using fake installation logs to hide malware activity has been identified by security researchers. The…
A new supply-chain threat is putting developers on alert. Security researchers warn that North Korean hackers have uploaded 26 malicious…
A recent surge in malicious activity involving North Korean-linked threat groups has been identified by cybersecurity researchers, revealing a coordinated…
