Tag: npm
116 articles

North Korean Hackers Intensify Campaign with New Malware Loader
North Korean hackers have taken their game to a new level, sneaking a dangerous malware loader into the trusted npm registry—putting thousands of developers and organizations at risk without them even knowing it. Stay ahead of the threat that’s shaking the very foundation of software supply chains worldwide.

North Korean Hackers Widen Contagious Interview Malware Campaign
Think twice before downloading that interview prep package—North Korean hackers are stealthily slipping dangerous malware into popular npm tools, turning trusted resources into digital traps for developers worldwide.

North Korean Hackers Spread Malware Loader in Expanding Campaign
North Korean hackers are stealthily spreading a new malware loader through popular npm packages, putting thousands of developers and organizations at risk in a chilling reminder that our digital supply chains are only as secure as their weakest link.

North Korean Hackers Target npm Registry with XORIndex Malware
North Korean hackers have unleashed a new wave of malware on the npm registry, cleverly hiding malicious code in popular JavaScript packages and putting millions of developers at risk—can we still trust the tools that power our software?

Alarming 188% Annual Increase in Malicious Open Source Packages
Discover the shocking 188% annual rise in malicious open source packages and its implications for developers and software security.

Surge of ‘Fake Interviews’ Deploys 35 NPM Packages to Distribute Malware
“Discover how a surge in fake interviews is leveraging 35 NPM packages to distribute malware, posing risks to developers and users alike.”

North Korea-Linked Cyberattack: 35 Malicious npm Packages Target Developers
North Korea-linked cyberattack reveals 35 malicious npm packages targeting developers, posing serious security risks and undermining software integrity.

PyPI, npm, and AI Tools Exploited in Malware Surge Targeting DevOps and Cloud Environments
Malware surge exploits PyPI, npm, and AI tools in DevOps and cloud environments. Learn how attackers leverage these vulnerabilities to compromise systems.

Global Supply Chain Cyberattack Targets npm and PyPI, Impacting Millions Worldwide
Global cyberattack on npm & PyPI disrupts supply chains, impacting millions worldwide. Uncover breach details now.

Dangerous npm Packages Disguised as Utilities That Delete Project Directories
Dangerous npm packages masquerade as utilities, but can delete your project directories. Learn how to spot and avoid these risky modules.

Supply chain attack hits Gluestack NPM packages with 960K weekly downloads
Supply chain attack strikes Gluestack’s NPM packages with 960K weekly downloads, exposing vulnerabilities that threaten project security and developer trust.

Malicious PyPI, npm, and Ruby Packages Exposed in Ongoing Open-Source Supply Chain Attacks
Malicious PyPI, npm, and Ruby packages jeopardize open-source supply chains. Secure your projects by updating dependencies and managing risks.

Over 70 Malicious npm and VS Code Packages Found Stealing Data and Crypto
Over 70 malicious npm and VS Code packages discovered stealing sensitive data and crypto. Secure your projects and protect your assets.

Reconnaissance Campaign Active on NPM Repository
A reconnaissance campaign on the NPM repository exposes vulnerabilities and drives urgent calls for stronger security protocols.

Malicious npm Package Leverages Unicode Steganography, Google Calendar as C2 Dropper
Malicious npm package uses Unicode steganography to disguise commands and Google Calendar as a C2 dropper, posing new cybersecurity challenges.

Malicious npm Packages Infect 3,200+ Cursor Users With Backdoor, Steal Credentials
Malicious npm packages compromise 3,200+ Cursor users with backdoors that steal credentials, revealing critical security vulnerabilities.

Supply chain attack hits npm package with 45,000 weekly downloads
Supply chain attack compromises an npm package with 45,000 weekly downloads. Learn how to secure your dependencies and mitigate emerging threats.

Major Supply Chain Attack: Ripple’s xrpl.js npm Package Compromised to Steal Private Keys
Ripple’s xrpl.js npm package was compromised in a major supply chain attack, leading to the theft of private keys from unsuspecting users.

Malicious npm Packages Imitate Telegram Bot API to Install SSH Backdoors on Linux
Malicious npm packages mimic the Telegram Bot API to install SSH backdoors on Linux, posing serious security risks for developers and systems.

The Art of Slopsquatting: Navigating the New Frontier of Cybersecurity Threats
Explore the unconventional lifestyle of slopsquatting, where creativity meets resourcefulness in a unique blend of art and living.