News

A new piece of malware is spreading through the popular tinycolor NPM library and more than 300 other packages, some of which ...
"Each published package becomes a new distribution vector: as soon as someone installs it, the worm executes, replicates, and ...
In a supply chain attack, attackers injected malware into NPM packages with over 2.6 billion weekly downloads after ...
Dozens of npm libraries, including a color library with over 2 million downloads a week, have been replaced with novel ...
An NPM supply-chain attack dating back to December 2021 used dozens of malicious NPM modules containing obfuscated Javascript code to compromise hundreds of downstream desktop apps and websites. As ...