product · 10 records
npm

Malicious npm Package Poses as Twilio Bug-Bounty Probe
Researchers discovered a malicious npm package that mimics a Twilio security tool to steal developer credentials and environment data.

Malicious npm Package indexed-btree Hid Its Loader in Runtime Code
A malicious npm package named indexed-btree hid its execution logic within runtime code to bypass new npm security restrictions.

WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
Researchers discovered 13 malicious npm packages distributing a new stealer called WeaselBiscuit that targets Chrome extension storage.

Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven Stealer
A threat actor created the PhantomRaven information stealer using LLMs to facilitate fraudulent bug bounty submissions.

Attackers target cPanel and WHM servers using compromised GitHub Actions repositories
Researchers report a large-scale campaign weaponizing compromised GitHub Actions repositories to target vulnerable cPanel and WebHost Manager servers for credential theft.

Two malicious npm packages infect Node.js environments with remote access trojan
Two compromised npm packages in the @joyfill namespace deliver a remote access trojan associated with DEV#POPPER when imported into Node.js environments.

Amazon links npm supply chain attacks to North Korea linked group
Amazon attributes the 2025 hijack of npm packages debug and chalk and related supply chain compromises to North Korea-linked group Sapphire Sleet despite disputed evidence of attribution.

Researchers warn AI coding agents are vulnerable to malicious package attacks
Researchers demonstrated that AI coding agents can be compromised by executing code from hallucinated package and repository names without verification.

GitHub and PyPI introduce time-based defenses against supply chain attacks
GitHub and PyPI have implemented time-based security measures in their dependency tools to mitigate supply-chain attacks.

Researchers identify seven malicious npm packages targeting the Vite ecosystem
Researchers uncovered a supply chain attack involving seven malicious npm packages targeting the Vite ecosystem that use a multi-tier blockchain command-and-control infrastructure to deliver a remote access trojan.