Nearly 800 npm packages hide a cross-platform RAT and infostealer behind fake README instructions.
A campaign of nearly 800 npm packages uses README lures and DNS tricks to deliver RATs on every platform.
The Mini Shai-Hulud worm stole publisher credentials, republished tainted packages, and burrowed into AI coding tools.
Amazon attributes the debug and chalk npm hijacks to the North Korean group behind the axios attack.
Five AsyncAPI npm packages with 2.9 million weekly downloads were trojanized after a GitHub Actions token theft.
The compromise cascaded from PyPI to npm to Packagist when a transitive dependency of pyannote-audio introduced the malicious Lightning package…
Backdoored versions of the Axios JavaScript library, downloaded by roughly 3% of its 100M weekly userbase, deployed cross-platform RATs via…
Sign in to your account