Skip to main content

Tag: npm

126 articles

Web developer's laptop open to npm registry page in coffee shop with notes and empty browser windows nearby.

Hackers Exploit npm Mirrors to Host Phishing Pages

Hackers are exploiting npm mirrors to host phishing pages by uploading malicious HTML files to the npm registry, which are then mirrored and can be accessed directly in a browser. This clever tactic turns the trusted registry into a free web host for malware, allowing threat actors to spread phishing pages under the guise of legitimate content.

Analyst 207
Developer workstation with laptop showing npm package page amidst coffee cups and notes, hinting at CAPTCHA scam.

npm Packages Host Fake Cloudflare CAPTCHA Pages via Unpkg Mirrors

Researchers uncovered a sneaky scam where attackers hide a fake Cloudflare CAPTCHA page inside harmless-looking npm packages, using mirrors to trick victims into revealing sensitive info. This clever tactic relies on exploiting trusted domains to deploy a ClickFix-style scam that redirects users to attacker-controlled infrastructure.

Analyst 207
Cluttered developer workstation with laptop, notes, and empty cans amidst computer hardware and dusty books.

Supply Chain Attacks Target SDLC's Overlooked Corners

Meet the ChainDrop npm worm, a sneaky threat that infiltrated over 400 packages, including popular libraries like keyv and cacheable-request, by hiding in plain sight within routine developer workflows. This highly evasive threat uses a three-step chain to steal sensitive tokens and secrets, spreading its reach with alarming ease.

Analyst 207
A coding workstation with a laptop, programming books, and notes on a quiet office desk.

Malware Packages Exploit Ethereum for C2 Communications

Malicious actors have cleverly exploited Ethereum to spread malware, with six suspicious npm packages found querying an attacker-controlled wallet to fetch additional malicious payloads. This sneaky tactic was uncovered by Sonatype Research Labs on August 10, revealing a new level of sophistication in cyber attacks.

Analyst 207
Cluttered software development workspace with laptop and terminal on a desk.

Malicious npm Packages Deliver Cross-Platform Malware

Nearly 800 malicious npm packages have been discovered delivering a potent cross-platform malware payload, including a remote access trojan and infostealer, via a sneaky trick that tricks developers into loading the malicious code. These packages use cleverly crafted names and README instructions to evade detection and deploy the WEL1DROPPER downloader.

Analyst 207
Cluttered software development workspace with laptop and coding tools.

Malware Worm Disrupts 440 npm Packages in Four Hours

In a shocking display of speed and agility, a malware worm spread its reach to over 440 npm packages in just four hours, leaving a trail of compromised code in its wake. The attack began with a single GitHub maintainer account, specifically targeting the popular data management interface package keyv, which boasts over 600 million monthly downloads.

Analyst 207
Rows of computer racks and cables in a brightly-lit Java software development environment.

npm Supply-Chain Attack Exposes Hundreds of Packages

A massive npm supply-chain attack has compromised at least 868 packages, with over 1,300 affected and a staggering 2 billion monthly downloads impacted. The self-propagating malware, ChainDrop, has spread rapidly, infecting widely-used caching utilities and leaving a trail of damage in its wake.

Analyst 207
Laptop screen displays npm package management interface amidst office workspace.

AWS Tracks North Korean Group in npm Supply Chain Attacks

AWS has uncovered a string of sneaky supply-chain attacks on popular npm libraries, and their threat intel team is pointing to a notorious North Korean group, known as Saphire Sleet, as the likely culprit. The attacks hit big-name libraries like axios, debug, and chalk, raising concerns about the security of the software supply chain.

Analyst 207
Cluttered coding workspace with laptop, notes, and coffee cups, with a blurred world map in the background.

Amazon Ties npm Hijack to North Korea's Sapphire Sleet

In a shocking supply-chain hijack, North Korea's Sapphire Sleet group compromised over 2 billion weekly downloads of popular npm packages, including debug and chalk, in a brazen attack tied to multiple other malicious campaigns. Amazon Threat Intelligence has linked this September 2025 incident to a string of attacks dating back to March 2025.

Analyst 207
Node.js package on a developer's workstation with code editor open, subtle blockchain diagram in background.

Compromised npm Packages Deliver DEV#POPPER Malware via Blockchain

Malicious npm packages have been discovered delivering DEV#POPPER malware via blockchain, with two beta releases in the @joyfill namespace containing a sneaky JavaScript implant that springs into action the moment Node.js loads the package. This stealthy implant can execute in any process that requires the compromised package, making it a serious threat.

Analyst 207
Cluttered developer workstation with laptop, coding tools, and subtle blockchain diagram in background.

Malicious Vite npm Packages Exploit Blockchain C2 for RAT Delivery

Security researchers have uncovered a sneaky campaign, dubbed ViteVenom, involving seven malicious npm packages that target Vite developers, executing malicious code as soon as they're imported. These packages, published in a matter of days, may have modest download counts, but their stealthy nature raises major red flags for the supply-chain community.

Analyst 207
Compromised software development environment with laptop and papers, hinting at a supply-chain intrusion.

Malicious AsyncAPI Packages Target npm Users with Credential-Stealing Malware

On July 14, a supply-chain intrusion briefly introduced trojanized AsyncAPI packages into the npm ecosystem, putting users at risk of credential-stealing malware. Five malicious releases in the @asyncapi namespace were downloaded hundreds of thousands of times during a four-hour window.

Analyst 207
Cluttered computer workstation with coding books and notes, laptop screen blank.

Compromised AsyncAPI Packages Deliver Multi-Stage Botnet Malware

Malicious actors have compromised several AsyncAPI packages, delivering a sophisticated multi-stage botnet malware that uses a command framework with six independent communication channels. The affected packages include @asyncapi/generator-helpers, @asyncapi/generator-components, @asyncapi/generator, and @asyncapi/specs in specific versions.

Analyst 207
Cluttered workstation with scattered papers, empty cans, and multiple screens displaying code amidst a sense of urgency.

Vulnerabilities Remain Unaddressed Despite Swift Remediation Efforts

Malicious npm packages have skyrocketed 451% year-over-year, highlighting a disturbing trend where old vulnerabilities continue to resurface and supply-chain abuse is scaling rapidly, putting organizations at risk. Despite swift remediation efforts, many critical vulnerabilities remain unaddressed.

Analyst 207
Laptops scattered in a brightly-lit university setting, hinting at cyber threat.

npm Packages Turned into DDoS Botnet via Student Proxies

In a shocking discovery, researchers uncovered 148 malicious npm packages that masqueraded as harmless student web proxies, but secretly turned browsers into a powerful DDoS botnet for nearly two weeks. These packages, cleverly disguised with benign names like "Lucide" and "Riverbend Tutoring," hid their true intentions beneath a façade of ads and monetization scripts.

Analyst 207
Developer workspace with npm package management page, terminal window, and software items on a brightly lit desk.

Jscrambler npm Package Infected with Infostealer Malware

A malicious version of the Jscrambler npm package was published, infecting nearly 1,500 downloads with infostealer malware within a two-hour window before being removed and replaced with a safe version. The incident was quickly contained, but users who downloaded the compromised package between releases 8.14 and 8.20 may be at risk.

Analyst 207
Developer workstation with code on laptop screen and GitHub/npm interface in background.

GitHub Compromise Injects Malicious npm Packages with Wallet-Key-Stealing Code

A malicious actor hijacked a trusted GitHub account and used it to inject wallet-key-stealing code into 18 npm packages, including Injective Labs' SDK, by exploiting the project's pipeline. This sneaky move allowed the attacker to spread the backdoor through a series of seemingly legitimate updates.

Analyst 207
A developer's clutter-free workstation with laptop, notebook, and coffee cup, set against a blurred background with a hint…

npm Package Infects Developers with Cryptocurrency Wallet Stealer

A malicious npm package, downloaded a staggering 50,000 times weekly, was briefly infected with code that stole cryptocurrency wallet private keys and sensitive seed phrases, putting countless developers at risk. The attack was launched after a contributor's GitHub account was compromised, allowing the hackers to spread the poisoned code across multiple projects.

Analyst 207
Developer workstation with laptop and notes, package manager interface on screen.

GitHub npm Tightens Security With Disabled Install Scripts

GitHub's latest npm update takes a giant leap in security by disabling install scripts by default, reducing supply-chain risks and giving developers more control. To adapt, plan to switch to trusted publishing or staged publishing with human approval for automated publishing.

Analyst 207
Developer workstation with laptop and coding items, hinting at vulnerability with faint shadow and ajar window.

Malicious SDKs Target Paysafe, Skrill Users with Credential Theft

Beware of malicious software development kits (SDKs) masquerading as legitimate Paysafe, Skrill, and Neteller tools, designed to secretly steal your credentials. Researchers uncovered 17 fake packages on popular platforms, putting users at risk of credential theft.

Analyst 207
Cluttered software development workspace with computer screens and terminals, one central laptop lid slightly ajar.

North Korean Hackers Publish 108 Malicious Packages in PolinRider Campaign

North Korean hackers have unleashed a massive wave of malware, publishing 108 malicious packages and web browser extensions across popular platforms like npm, Packagist, Go, and Google Chrome as part of their sneaky PolinRider campaign. This ongoing operation has already produced 162 malicious release artifacts and compromised thousands of systems worldwide.

Analyst 207
Developer workspace with laptop, monitor, and notes, overlooking cityscape through window.

North Korea-Linked npm Packages Target Developers with Stealthy Data Theft

Malicious npm packages, linked to North Korean threat actors, are impersonating popular tools to trick developers into handing over sensitive data. These sneaky packages masquerade as legitimate polyfill tools, making them hard to spot during a quick review.

Analyst 207
Cluttered developer workspace with laptop, papers, and coffee cups.

Malware Exploits VS Code Tasks in Hijacked Packages

Researchers have uncovered a sneaky malware attack that hides in Visual Studio Code tasks, masquerading as a harmless "eslint-check" task that springs into action the moment you open a compromised package directory in VS Code. The malware cleverly disguises its executable payload as a font file, allowing it to slip past defenses undetected.

Analyst 207
Software development workspace with laptop, screens, and tools, hinting at network infrastructure.

Miasma Malware Poisons Over 20 npm Packages

In a lightning-fast attack, hackers poisoned over 20 npm packages with Miasma malware, completing the coordinated operation in under three seconds. The attackers compromised an npm maintainer account to publish tainted updates to popular packages.

Analyst 207