Tag

#npm

45 stories taggednpm.

Photoreal editorial shot of a developer's darkened desk, an open laptop showing rows of green package names in a terminal, one line highlighted in red, faint bl
Threat Intelligence

Fake npm Calendar Tools Hid an AI-Powered Linux Backdoor

Researchers found 14 booby-trapped packages on the popular open-source library npm, each quietly installing a remote-control tool called RedC2 4.0 on Linux machines.

4 min read
Aerial top-down view of a vast cloud data center facility at dusk, rows of server buildings casting long shadows, with small warning amber lights glowing along
AI Security

Criminals Are Using AI Like a Work Tool. Researchers Have the Receipts.

Two major studies show hackers using AI assistants to write malicious code, dodge safety filters, and attack in hours rather than weeks. Cloud activity tied to this shift jumped 171 percent in the first half of 2026.

5 min read
Photoreal editorial shot of a developer's darkened desk, an open laptop showing rows of green package names in a terminal, one line highlighted in red, faint bl
Threat Intelligence

Malicious npm Packages Hide Attacker Servers Inside Empty Ethereum Transactions

Researchers found two booby-trapped code libraries pulling instructions from fake wallet addresses on the Ethereum blockchain, a twist on the EtherHiding trick now dubbed NullReceiver.

4 min read
Photoreal news-editorial style, 16:9 framing, edge-to-edge composition
Vulnerabilities

Credential-Stealing Worm Spreads Across npm Packages

A worm targeting npm packages has affected hundreds of software components, raising security concerns for developers.

2 min read
Full-frame photoreal editorial shot of a developer's dark workstation at night, the glow of a large monitor showing abstract lines of code with a single line hi
Threat Intelligence

Fake npm Packages Pose as Alibaba Developer Tools, Drop Remote-Control Malware

Researchers found 18 booby-trapped packages on the npm registry aimed at Chinese-speaking developers, using a classic name-squatting trick to smuggle in a cross-platform remote access trojan.

4 min read
Photoreal editorial 16:9 image of a darkened developer workstation with a MacBook open to a terminal window, blurred cryptocurrency price tickers reflected in t
Threat Intelligence

Amazon Traces September npm Hijack of Debug and Chalk to North Korean Hackers

What looked like a wallet-draining crypto heist ten months ago now points to Pyongyang, according to fresh analysis from Amazon.

3 min read
A digital representation of software supply chain attack with code streams and lock graphics
Threat Intelligence

Booby-trapped @joyfill npm packages hide a remote-control trojan

Two beta versions of the popular Joyfill JavaScript packages were tampered with to plant malware that runs the moment a developer imports them.

4 min read
A close-up of a server room with rows of glowing servers, symbolizing security and data protection
Policy & Regulation

GitHub and PyPI Add Waiting Periods to Slow Down Supply-Chain Attacks

Dependabot now waits three days before pulling in new package versions, and PyPI blocks file uploads to releases older than 14 days.

4 min read
Photoreal news-editorial 16:9 image of a glowing computer monitor in a dimly lit office showing dense lines of green and white code, with a physical padlock sit
AI Security

Five Major AI Coding Tools Keep Inventing the Same Fake Software Packages

A researcher found 127 made-up package names shared across ChatGPT, Claude, Gemini, and DeepSeek, and 53 of those names are still free for criminals to register today.

3 min read
Full-frame photoreal news-editorial image of a dimly lit developer workstation at night, glowing monitor showing rows of package manager install output in green
Threat Intelligence

Seven booby-trapped npm packages hit Vite developers with blockchain-controlled malware

Researchers at Checkmarx say the ViteVenom campaign hides its command server across four different cryptocurrency networks, making it unusually hard to shut down.

3 min read
Extreme close-up of a glowing green terminal screen filled with cascading lines of package dependency text and vulnerability identifiers, shot from a low angle
Vulnerabilities

Two Popular Coding Tools Poisoned With Malware in Back-to-Back Supply Chain Attacks

Criminals hijacked developer credentials to slip malicious code into widely used JavaScript packages, putting any computer that installed them at serious risk.

3 min read
Full-frame overhead view of a developer's dark desk, glowing keyboard, terminal windows on a monitor showing package installation progress with faint red warnin
Threat Intelligence

Trojanised AsyncAPI packages slip onto npm, hitting a library downloaded 2.25 million times a week

Attackers hijacked a GitHub build pipeline on 14 July to publish five poisoned versions of AsyncAPI tools, wiring in a stealthy info-stealer that talks to its operators over Ethereum and peer-to-peer networks.

4 min read
Photoreal editorial shot of a developer's darkened desk, an open laptop showing rows of green package names in a terminal, one line highlighted in red, faint bl
Threat Intelligence

Hijacked AsyncAPI npm Packages Slipped a Botnet Loader Into Developer Machines

Four packages under the popular @asyncapi namespace were tampered with to deliver a multi-stage malware loader, in the latest reminder that the open-source supply chain is a soft target.

3 min read
A weathered combination padlock resting on a cracked concrete surface, surrounded by a tangled web of thin copper wires spreading outward in all directions, pho
Identity & Access

Poisoned Developer Tool Downloaded Nearly 1,500 Times Before Anyone Noticed

Criminals hijacked the publishing credentials for a widely used JavaScript security package and slipped malware into four releases over a single weekend. Developers who installed any of those versions may have handed over passwords, crypto-wallet keys, and cloud access tokens without knowing it.

3 min read
Photoreal editorial image, 16:9 full-frame edge-to-edge composition
Threat Intelligence

Fake Student Proxies on npm Turned Browsers Into a DDoS Weapon

Researchers at JFrog say 148 malicious packages used the npm registry as free hosting for a booby-trapped proxy site, quietly enlisting students' browsers into a two-week attack campaign in May.

3 min read
© 2026 Threat Vectr