company · 2 records
Aikido

Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
Compromised MemTensor software packages are distributing a cross-platform credential-stealing malware.
1 outlet

Amazon links npm supply chain attacks to North Korea linked group
Amazon attributes the 2025 hijack of npm packages debug and chalk and related supply chain compromises to North Korea-linked group Sapphire Sleet despite disputed evidence of attribution.
1 outlet