Tag

#npm

29 stories taggednpm.

Illustration: A darkened developer workspace at night: an open laptop showing a blurred terminal with green package-install
Breaches

How a poisoned coding library led to 170 private repos being copied at CrowdSec

A French security firm says a departing employee's laptop was infected through the TanStack npm supply-chain attack in May. The fallout reached its GitHub.

3 min read
A developer's workspace with an npm package manager interface open on the monitor, showing package listings and download counts, with a phishing login page prev
Threat Intelligence

Criminals Turn npm Into Free Hosting for Fake Cloudflare Login Traps

Researchers found 24 packages on the npm registry being used not to poison developers, but as free web hosting for phishing pages that pretend to be Cloudflare's human-check screen.

3 min read
A developer's workstation with a code editor showing package dependencies and terminal windows with security warnings, with red alert indicators on the screen
Threat Intelligence

Fake npm Calendar Tools Hid an AI-Powered Linux Backdoor

Researchers found 14 booby-trapped packages on the popular open-source library npm, each quietly installing a remote-control tool called RedC2 4.0 on Linux machines.

3 min read
A criminal operation workspace visualization showing multiple screens with AI chatbot interfaces open, malicious code being generated and refined, with cloud ac
AI Security

Criminals Are Using AI Like a Work Tool. Researchers Have the Receipts.

Two major studies show hackers using AI assistants to write malicious code, dodge safety filters, and compress attacks from weeks into hours. Cloud activity tied to this shift jumped 171 percent in the first half of 2026.

4 min read
A code repository or npm package manager interface on screen showing package listings, with an Ethereum blockchain explorer window open in the background displa
Threat Intelligence

Malicious npm Packages Hide Attacker Servers Inside Empty Ethereum Transactions

Researchers found two booby-trapped code libraries pulling instructions from fake wallet addresses on the Ethereum blockchain, a twist on the EtherHiding trick now dubbed NullReceiver.

4 min read
A developer's terminal window showing npm package listings with multiple entries highlighted in red, illustrating how a single compromised package spawned infec
Vulnerabilities

Credential-Stealing Worm Spreads Across npm Packages

A worm seeded in a single npm package replicated into hundreds of others on August 4, 2026, with two security firms putting the damage count at different but alarming numbers.

2 min read
Developer workspace with code editor displaying npm package registry interface, malicious package listings highlighted, security scanning tools running in backg
Threat Intelligence

Fake npm Packages Pose as Alibaba Developer Tools, Drop Remote-Control Malware

Researchers found 18 booby-trapped packages on the npm registry aimed at Chinese-speaking developers, using a classic name-squatting trick to smuggle in a cross-platform remote access trojan.

4 min read
An npm package repository screen showing the hijacked 'Debug' and 'Chalk' packages with suspicious version uploads and download statistics, with attribution mar
Threat Intelligence

Amazon Traces September npm Hijack of Debug and Chalk to North Korean Hackers

What looked like a wallet-draining crypto heist ten months ago now points to Pyongyang, according to fresh analysis from Amazon.

3 min read
A developer's IDE with the Joyfill package imported, malicious code highlighted in the dependency tree, a remote-control trojan's command structure revealed in
Threat Intelligence

Booby-trapped @joyfill npm packages hide a remote-control trojan

Two beta versions of the popular Joyfill JavaScript packages were tampered with to plant malware that runs the moment a developer imports them.

4 min read
A dependency management dashboard showing package update timelines with new calendar blocking periods inserted, slowing the rate of automatic pulls from reposit
Policy & Regulation

GitHub and PyPI Add Waiting Periods to Slow Down Supply-Chain Attacks

Dependabot now waits three days before pulling in new package versions, and PyPI blocks file uploads to releases older than 14 days.

4 min read
A split-screen comparison showing identical package names being suggested by different AI chatbot interfaces, with a criminal's hand holding a domain registrati
AI Security

Five Major AI Coding Tools Keep Inventing the Same Fake Software Packages

A researcher found 127 made-up package names shared across ChatGPT, Claude, Gemini, and DeepSeek, and 53 of those names are still free for criminals to register today.

3 min read
Illustration: a dimly lit developer workstation at night
Threat Intelligence

Seven booby-trapped npm packages hit Vite developers with blockchain-controlled malware

Researchers at Checkmarx say the ViteVenom campaign hides its command server across cryptocurrency networks, making it unusually hard to shut down.

3 min read
Illustration: a glowing green terminal screen filled with cascading lines of package dependency text and vulnerability
Vulnerabilities

Two Popular Coding Tools Poisoned With Malware in Back-to-Back Supply Chain Attacks

Criminals hijacked developer credentials to slip malicious code into widely used JavaScript packages, putting any computer that installed them at serious risk.

3 min read
Illustration: a developer's dark desk, glowing keyboard
Threat Intelligence

Trojanised AsyncAPI packages slip onto npm, hitting a library downloaded 2.25 million times a week

Attackers hijacked a GitHub build pipeline on 14 July to publish five poisoned versions of AsyncAPI tools, wiring in a stealthy info-stealer that talks to its operators over Ethereum and peer-to-peer networks.

3 min read
Illustration: a developer's darkened desk, an open laptop showing rows of green package names in a terminal
Threat Intelligence

Hijacked AsyncAPI npm Packages Slipped a Botnet Loader Into Developer Machines

Four packages under the popular @asyncapi namespace were tampered with to deliver a multi-stage malware loader, in the latest reminder that the open-source supply chain is a soft target.

3 min read
© 2026 Threat Vectr