News

A new supply-chain attack compromised at least 187 npm packages, targeting developer secrets across software ...
Security researchers have identified at least 187 npm packages compromised in an ongoing supply chain attack. The coordinated ...
The novel malware strain is being dubbed Shai-Hulud — after the name for the giant sandworms in Frank Herbert’s Dune novel ...
Hackers injected malicious code into nearly a dozen 20 NPM packages with billions of weekly downloads in a software supply chain attack after phishing a maintainer’s account.
Open source software is a pivotal infrastructural component of the modern internet, but its unique security dilemmas can, on ...
Shai-Hulud is the third major supply chain attack targeting the NPM ecosystem after the s1ngularity attack and the recent ...
Dozens of npm libraries, including a color library with over 2 million downloads a week, have been replaced with novel ...
Hulud" has compromised hundreds of packages in the npm repository with a self-replicating worm that steals secrets like API key, tokens, and cloud credentials and sends them to external servers that ...
Hackers planted malicious code in open source software packages with more than 2 billion weekly updates in what is likely to ...
"Each published package becomes a new distribution vector: as soon as someone installs it, the worm executes, replicates, and ...
According to ReversingLabs' 2025 Software Supply Chain Security Report, 14 of the 23 crypto-related malicious campaigns in ...
The malware was found in 18 npm packages that together are usually downloaded over 2 billion times per week. But the security ...