A campaign distributing nearly 800 malicious npm packages with typo-squatted AI-generated names delivers a powerful RAT and infostealer targeting Windows, Mac, and Linux environments, posing a significant threat to developers and enterprises using npm packages.
A compromise affecting the Keyv and Cacheable npm packages is leading to reconsideration of token revocation policies due to an active malware that triggers upon premature token revocation.
The ChainDrop malware has compromised over 1,300 npm packages, impacting software supply chain security with billions of downloads monthly.
Amazon attributes multiple supply chain attacks on the Debug and Chalk npm packages to North Korean state-sponsored hackers, exposing risks to open-source software security.
Seven malicious npm packages in the Vite ecosystem use a four-tier blockchain-based command-and-control infrastructure to deploy RAT malware, expanding the ChainVeil supply chain threat.
A malicious version of the Jscrambler npm package containing infostealer malware was published and downloaded nearly 1,500 times, posing risks to developers and users of this client-side security tool.
GitHub released npm version 12 with install scripts disabled by default and deprecated granular access tokens used to bypass 2FA. These changes reduce the risk of supply chain attacks for developers and security teams.