Skip to main content

Tag: package poisoning

2 articles

Cluttered software development workspace with laptop, papers, and cables.

Npm Worm Exploits Hundreds of Packages via Keyv Link

Hundreds of packages in the npm registry have been compromised by a worm exploiting a vulnerability in the Keyv library, with 353 poisoned versions across 79 package names verified. This malicious campaign uses a preinstall lifecycle command to spread and harvest sensitive credentials and secrets from various sources.

Analyst 207
Developer workstation with laptop and blurred terminal screen, highlighting supply chain security concerns.

PyPI Packages Poisoned in Hades Supply Chain Attack

Malicious actors have launched a supply-chain attack on the Python Package Index (PyPI), infecting 19 packages with 37 tainted versions that can download and execute a hidden JavaScript payload. This sneaky Hades campaign uses poisoned Python packages to spread its reach, putting developers and users at risk.

Analyst 207