Skip to main content

Tag: npm

116 articles

North Korean Hackers Intensify Campaign with New Malware Loader

North Korean Hackers Intensify Campaign with New Malware Loader

North Korean hackers have taken their game to a new level, sneaking a dangerous malware loader into the trusted npm registry—putting thousands of developers and organizations at risk without them even knowing it. Stay ahead of the threat that’s shaking the very foundation of software supply chains worldwide.

Analyst 207
North Korean Hackers Widen Contagious Interview Malware Campaign

North Korean Hackers Widen Contagious Interview Malware Campaign

Think twice before downloading that interview prep package—North Korean hackers are stealthily slipping dangerous malware into popular npm tools, turning trusted resources into digital traps for developers worldwide.

Analyst 207
North Korean Hackers Spread Malware Loader in Expanding Campaign

North Korean Hackers Spread Malware Loader in Expanding Campaign

North Korean hackers are stealthily spreading a new malware loader through popular npm packages, putting thousands of developers and organizations at risk in a chilling reminder that our digital supply chains are only as secure as their weakest link.

Analyst 207
North Korean Hackers Target npm Registry with XORIndex Malware

North Korean Hackers Target npm Registry with XORIndex Malware

North Korean hackers have unleashed a new wave of malware on the npm registry, cleverly hiding malicious code in popular JavaScript packages and putting millions of developers at risk—can we still trust the tools that power our software?

Analyst 207
Alarming 188% Annual Increase in Malicious Open Source Packages

Alarming 188% Annual Increase in Malicious Open Source Packages

Discover the shocking 188% annual rise in malicious open source packages and its implications for developers and software security.

Analyst 207
Surge of ‘Fake Interviews’ Deploys 35 NPM Packages to Distribute Malware

Surge of ‘Fake Interviews’ Deploys 35 NPM Packages to Distribute Malware

“Discover how a surge in fake interviews is leveraging 35 NPM packages to distribute malware, posing risks to developers and users alike.”

Analyst 207
North Korea-Linked Cyberattack: 35 Malicious npm Packages Target Developers

North Korea-Linked Cyberattack: 35 Malicious npm Packages Target Developers

North Korea-linked cyberattack reveals 35 malicious npm packages targeting developers, posing serious security risks and undermining software integrity.

Analyst 207
PyPI, npm, and AI Tools Exploited in Malware Surge Targeting DevOps and Cloud Environments

PyPI, npm, and AI Tools Exploited in Malware Surge Targeting DevOps and Cloud Environments

Malware surge exploits PyPI, npm, and AI tools in DevOps and cloud environments. Learn how attackers leverage these vulnerabilities to compromise systems.

Analyst 207
Global Supply Chain Cyberattack Targets npm and PyPI, Impacting Millions Worldwide

Global Supply Chain Cyberattack Targets npm and PyPI, Impacting Millions Worldwide

Global cyberattack on npm & PyPI disrupts supply chains, impacting millions worldwide. Uncover breach details now.

Analyst 207
Dangerous npm Packages Disguised as Utilities That Delete Project Directories

Dangerous npm Packages Disguised as Utilities That Delete Project Directories

Dangerous npm packages masquerade as utilities, but can delete your project directories. Learn how to spot and avoid these risky modules.

Analyst 207
Supply chain attack hits Gluestack NPM packages with 960K weekly downloads

Supply chain attack hits Gluestack NPM packages with 960K weekly downloads

Supply chain attack strikes Gluestack’s NPM packages with 960K weekly downloads, exposing vulnerabilities that threaten project security and developer trust.

Analyst 207
Malicious PyPI, npm, and Ruby Packages Exposed in Ongoing Open-Source Supply Chain Attacks

Malicious PyPI, npm, and Ruby Packages Exposed in Ongoing Open-Source Supply Chain Attacks

Malicious PyPI, npm, and Ruby packages jeopardize open-source supply chains. Secure your projects by updating dependencies and managing risks.

Analyst 207
Over 70 Malicious npm and VS Code Packages Found Stealing Data and Crypto

Over 70 Malicious npm and VS Code Packages Found Stealing Data and Crypto

Over 70 malicious npm and VS Code packages discovered stealing sensitive data and crypto. Secure your projects and protect your assets.

Analyst 207
Reconnaissance Campaign Active on NPM Repository

Reconnaissance Campaign Active on NPM Repository

A reconnaissance campaign on the NPM repository exposes vulnerabilities and drives urgent calls for stronger security protocols.

Analyst 207
Malicious npm Package Leverages Unicode Steganography, Google Calendar as C2 Dropper

Malicious npm Package Leverages Unicode Steganography, Google Calendar as C2 Dropper

Malicious npm package uses Unicode steganography to disguise commands and Google Calendar as a C2 dropper, posing new cybersecurity challenges.

Analyst 207
Malicious npm Packages Infect 3,200+ Cursor Users With Backdoor, Steal Credentials

Malicious npm Packages Infect 3,200+ Cursor Users With Backdoor, Steal Credentials

Malicious npm packages compromise 3,200+ Cursor users with backdoors that steal credentials, revealing critical security vulnerabilities.

Analyst 207
Supply chain attack hits npm package with 45,000 weekly downloads

Supply chain attack hits npm package with 45,000 weekly downloads

Supply chain attack compromises an npm package with 45,000 weekly downloads. Learn how to secure your dependencies and mitigate emerging threats.

Analyst 207
Major Supply Chain Attack: Ripple’s xrpl.js npm Package Compromised to Steal Private Keys

Major Supply Chain Attack: Ripple’s xrpl.js npm Package Compromised to Steal Private Keys

Ripple’s xrpl.js npm package was compromised in a major supply chain attack, leading to the theft of private keys from unsuspecting users.

Analyst 207
Malicious npm Packages Imitate Telegram Bot API to Install SSH Backdoors on Linux

Malicious npm Packages Imitate Telegram Bot API to Install SSH Backdoors on Linux

Malicious npm packages mimic the Telegram Bot API to install SSH backdoors on Linux, posing serious security risks for developers and systems.

Analyst 207
The Art of Slopsquatting: Navigating the New Frontier of Cybersecurity Threats

The Art of Slopsquatting: Navigating the New Frontier of Cybersecurity Threats

Explore the unconventional lifestyle of slopsquatting, where creativity meets resourcefulness in a unique blend of art and living.

Analyst 207