tag
npm
33 posts
- Active Supply Chain Attack Compromises @antv Packages on npm
- Popular node-ipc npm Package Infected with Credential Stealer
- Weekly Recap — 2026-05-11 -> 2026-05-18
- Mini Shai-Hulud: The Worm Returns and Goes Public
- TanStack npm Packages Compromised in Ongoing Mini Shai-Hulud Supply-Chain Attack
- 5 Malicious NuGet Packages Impersonate Chinese UI Libraries to Distribute Crypto Wallet and Credential Stealer
- Mini Shai-Hulud Spreads to Packagist: Malicious Intercom PHP Package Follows npm Compromise
- Intercom’s npm Package Compromised in Ongoing Mini Shai-Hulud Worm Attack
- lightning PyPI Package Compromised in Supply Chain Attack
- TeamPCP-Linked Supply Chain Attack Hits SAP CAP and Cloud MTA npm Packages
- Malicious npm Package Brand-Squats TanStack to Exfiltrate Environment Variables
- 'Mini Shai-Hulud' supply chain attack targets SAP npm packages
- Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign
- Supply Chain Compromise Impacts Axios Node Package Manager
- Don't Kill the Goose That Lays the Golden Eggs
- Feross on TBPN: How North Korea Hijacked Axios
- Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
- Supply Chain Attacks Surge in March 2026 | ThreatLabz
- Intelligence Center
- Axios Maintainer Confirms Social Engineering Attack Behind npm Compromise
- The Hidden Blast Radius of the Axios Compromise
- Supply Chain Attack on Axios Pulls Malicious Dependency from npm
- STARDUST CHOLLIMA Likely Compromises Axios npm Package
- How we caught the Axios supply chain attack
- Mitigating the Axios npm supply chain compromise
- Inside the Axios supply chain compromise - one RAT to rule them all
- Elastic releases detections for the Axios supply chain compromise
- North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack
- Axios npm package compromised to deploy malware
- Axios NPM Package Compromised: Supply Chain Attack Hits JavaScript HTTP Client with 100M+ Weekly Downloads
- 5 Malicious npm Packages Typosquat Solana and Ethereum Libraries to Steal Private Keys
- CanisterWorm: npm Publisher Compromise Deploys Backdoor Across 29+ Packages
- Weekly Recap — 2026-05-04 -> 2026-05-11