#npm
45 stories taggednpm.

Fake npm Calendar Tools Hid an AI-Powered Linux Backdoor
Researchers found 14 booby-trapped packages on the popular open-source library npm, each quietly installing a remote-control tool called RedC2 4.0 on Linux machines.

Criminals Are Using AI Like a Work Tool. Researchers Have the Receipts.
Two major studies show hackers using AI assistants to write malicious code, dodge safety filters, and attack in hours rather than weeks. Cloud activity tied to this shift jumped 171 percent in the first half of 2026.

Malicious npm Packages Hide Attacker Servers Inside Empty Ethereum Transactions
Researchers found two booby-trapped code libraries pulling instructions from fake wallet addresses on the Ethereum blockchain, a twist on the EtherHiding trick now dubbed NullReceiver.

Credential-Stealing Worm Spreads Across npm Packages
A worm targeting npm packages has affected hundreds of software components, raising security concerns for developers.

Fake npm Packages Pose as Alibaba Developer Tools, Drop Remote-Control Malware
Researchers found 18 booby-trapped packages on the npm registry aimed at Chinese-speaking developers, using a classic name-squatting trick to smuggle in a cross-platform remote access trojan.

Amazon Traces September npm Hijack of Debug and Chalk to North Korean Hackers
What looked like a wallet-draining crypto heist ten months ago now points to Pyongyang, according to fresh analysis from Amazon.

Booby-trapped @joyfill npm packages hide a remote-control trojan
Two beta versions of the popular Joyfill JavaScript packages were tampered with to plant malware that runs the moment a developer imports them.

GitHub and PyPI Add Waiting Periods to Slow Down Supply-Chain Attacks
Dependabot now waits three days before pulling in new package versions, and PyPI blocks file uploads to releases older than 14 days.

Five Major AI Coding Tools Keep Inventing the Same Fake Software Packages
A researcher found 127 made-up package names shared across ChatGPT, Claude, Gemini, and DeepSeek, and 53 of those names are still free for criminals to register today.

Seven booby-trapped npm packages hit Vite developers with blockchain-controlled malware
Researchers at Checkmarx say the ViteVenom campaign hides its command server across four different cryptocurrency networks, making it unusually hard to shut down.

Two Popular Coding Tools Poisoned With Malware in Back-to-Back Supply Chain Attacks
Criminals hijacked developer credentials to slip malicious code into widely used JavaScript packages, putting any computer that installed them at serious risk.

Trojanised AsyncAPI packages slip onto npm, hitting a library downloaded 2.25 million times a week
Attackers hijacked a GitHub build pipeline on 14 July to publish five poisoned versions of AsyncAPI tools, wiring in a stealthy info-stealer that talks to its operators over Ethereum and peer-to-peer networks.

Hijacked AsyncAPI npm Packages Slipped a Botnet Loader Into Developer Machines
Four packages under the popular @asyncapi namespace were tampered with to deliver a multi-stage malware loader, in the latest reminder that the open-source supply chain is a soft target.

Poisoned Developer Tool Downloaded Nearly 1,500 Times Before Anyone Noticed
Criminals hijacked the publishing credentials for a widely used JavaScript security package and slipped malware into four releases over a single weekend. Developers who installed any of those versions may have handed over passwords, crypto-wallet keys, and cloud access tokens without knowing it.

Fake Student Proxies on npm Turned Browsers Into a DDoS Weapon
Researchers at JFrog say 148 malicious packages used the npm registry as free hosting for a booby-trapped proxy site, quietly enlisting students' browsers into a two-week attack campaign in May.