#npm
29 stories taggednpm.

How a poisoned coding library led to 170 private repos being copied at CrowdSec
A French security firm says a departing employee's laptop was infected through the TanStack npm supply-chain attack in May. The fallout reached its GitHub.

Criminals Turn npm Into Free Hosting for Fake Cloudflare Login Traps
Researchers found 24 packages on the npm registry being used not to poison developers, but as free web hosting for phishing pages that pretend to be Cloudflare's human-check screen.

Fake npm Calendar Tools Hid an AI-Powered Linux Backdoor
Researchers found 14 booby-trapped packages on the popular open-source library npm, each quietly installing a remote-control tool called RedC2 4.0 on Linux machines.

Criminals Are Using AI Like a Work Tool. Researchers Have the Receipts.
Two major studies show hackers using AI assistants to write malicious code, dodge safety filters, and compress attacks from weeks into hours. Cloud activity tied to this shift jumped 171 percent in the first half of 2026.

Malicious npm Packages Hide Attacker Servers Inside Empty Ethereum Transactions
Researchers found two booby-trapped code libraries pulling instructions from fake wallet addresses on the Ethereum blockchain, a twist on the EtherHiding trick now dubbed NullReceiver.

Credential-Stealing Worm Spreads Across npm Packages
A worm seeded in a single npm package replicated into hundreds of others on August 4, 2026, with two security firms putting the damage count at different but alarming numbers.

Fake npm Packages Pose as Alibaba Developer Tools, Drop Remote-Control Malware
Researchers found 18 booby-trapped packages on the npm registry aimed at Chinese-speaking developers, using a classic name-squatting trick to smuggle in a cross-platform remote access trojan.

Amazon Traces September npm Hijack of Debug and Chalk to North Korean Hackers
What looked like a wallet-draining crypto heist ten months ago now points to Pyongyang, according to fresh analysis from Amazon.

Booby-trapped @joyfill npm packages hide a remote-control trojan
Two beta versions of the popular Joyfill JavaScript packages were tampered with to plant malware that runs the moment a developer imports them.

GitHub and PyPI Add Waiting Periods to Slow Down Supply-Chain Attacks
Dependabot now waits three days before pulling in new package versions, and PyPI blocks file uploads to releases older than 14 days.

Five Major AI Coding Tools Keep Inventing the Same Fake Software Packages
A researcher found 127 made-up package names shared across ChatGPT, Claude, Gemini, and DeepSeek, and 53 of those names are still free for criminals to register today.

Seven booby-trapped npm packages hit Vite developers with blockchain-controlled malware
Researchers at Checkmarx say the ViteVenom campaign hides its command server across cryptocurrency networks, making it unusually hard to shut down.

Two Popular Coding Tools Poisoned With Malware in Back-to-Back Supply Chain Attacks
Criminals hijacked developer credentials to slip malicious code into widely used JavaScript packages, putting any computer that installed them at serious risk.

Trojanised AsyncAPI packages slip onto npm, hitting a library downloaded 2.25 million times a week
Attackers hijacked a GitHub build pipeline on 14 July to publish five poisoned versions of AsyncAPI tools, wiring in a stealthy info-stealer that talks to its operators over Ethereum and peer-to-peer networks.

Hijacked AsyncAPI npm Packages Slipped a Botnet Loader Into Developer Machines
Four packages under the popular @asyncapi namespace were tampered with to deliver a multi-stage malware loader, in the latest reminder that the open-source supply chain is a soft target.