Tag

#javascript

8 stories taggedjavascript.

A Telegram chat window on a desktop with an HTML export file icon visible, JavaScript code flowing from the HTML file toward a message history folder in the fil
Vulnerabilities

Telegram Desktop bug let a hidden script steal chats from saved conversations

Researchers at ExPatch showed how a single bot message could hide JavaScript inside an HTML chat export, then quietly copy every message when the file was opened.

3 min read
A code editor showing JavaScript sandbox security functions with breach points highlighted, surrounded by documentation windows displaying vulnerability details
Vulnerabilities

A popular JavaScript sandbox has a hole in it, and the fix is to stop using it

Researchers found a way out of isolated-vm, an open-source tool used to safely run untrusted code. The maintainer says the project is unmaintained and users should migrate.

3 min read
A developer's IDE with the Joyfill package imported, malicious code highlighted in the dependency tree, a remote-control trojan's command structure revealed in
Threat Intelligence

Booby-trapped @joyfill npm packages hide a remote-control trojan

Two beta versions of the popular Joyfill JavaScript packages were tampered with to plant malware that runs the moment a developer imports them.

4 min read
A weathered combination padlock resting on a cracked concrete surface, surrounded by a tangled web of thin copper wires spreading outward in all directions, pho
Identity & Access

Poisoned Developer Tool Downloaded Nearly 1,500 Times Before Anyone Noticed

Criminals hijacked the publishing credentials for a widely used JavaScript security package and slipped malware into four releases over a single weekend. Developers who installed any of those versions may have handed over passwords, crypto-wallet keys, and cloud access tokens without knowing it.

3 min read
Illustration: a developer's dark workstation at night
Threat Intelligence

Malicious Jscrambler npm package stole developer secrets for two hours before takedown

A poisoned release of the Jscrambler npm package was downloaded almost 1,500 times, scooping up cloud keys, wallet seed phrases and browser credentials before the company pulled it.

3 min read
Illustration: a darkened developer workstation with a terminal window glowing on the monitor
Threat Intelligence

Booby-trapped jscrambler npm release runs infostealer the moment you install it

Version 8.14.0 of a popular JavaScript protection package shipped with a hidden payload that fires during install, no code changes required from the developer.

3 min read
Illustration: a darkened developer workstation with a large monitor showing abstract cascading package dependency graphs
Policy & Regulation

npm 12 Turns Off Auto-Run Install Scripts to Blunt Supply Chain Attacks

GitHub's package manager for JavaScript now ships with a safer default, and it retires a token type that let developers skip two-factor login.

3 min read
Illustration for the story: Fake Rollup Helper Packages on npm Traced to North Korean Hackers
Threat Intelligence

Fake Rollup Helper Packages on npm Traced to North Korean Hackers

Two look-alike JavaScript packages copied a popular developer tool line-for-line, then quietly opened a back door onto the machines of anyone who installed them.

3 min read
© 2026 Threat Vectr