Tag: NPM


  • Hackers Use npm Mirrors to Host Phishing Redirect Pages

    Researchers have identified an npm mirror phishing technique that uses package registries and public mirrors to host malicious redirect pages. Instead of infecting developers who download a package, attackers store harmful HTML files inside npm packages. Mirror services then copy those files and make them available from trusted developer-related domains. This approach can make phishing…

  • npm Worm Infects 444 Packages With 2 Billion Monthly Downloads

    A new npm worm has infected at least 444 software packages and more than 2,000 package versions, putting applications with over two billion combined monthly installs at risk. The malware is spreading through stolen developer credentials and automatically poisoning additional packages. Security researchers warn that affected organisations should assume their systems and secrets may have…

  • npm Security Changes Target Software Supply Chain Risks

    Software supply chain attacks have become one of the biggest threats facing developers, and npm is preparing significant changes to reduce that risk. GitHub announced new security controls for npm that will limit automatic package installation behaviors and require developers to explicitly approve actions that attackers commonly abuse. The changes represent one of the most…

  • NPM Package Attack Hits Hundreds of Open-Source Libraries

    A large npm package attack has compromised hundreds of open-source libraries used by developers worldwide. Researchers warned that the campaign exposed software projects, developer systems, and CI/CD environments to credential theft and destructive malware activity. The incident affected packages with millions of downloads and raised fresh concerns about the growing threat of software supply chain…

  • NPM Supply Chain Attack Hits 40 Packages

    A new NPM supply chain attack has compromised more than 40 packages, exposing millions of developers to hidden malware. One of the affected libraries, tinycolor, recorded over two million weekly downloads before its compromise. The incident highlights the growing risks of supply chain attacks in open-source ecosystems. How the Attack Worked Attackers targeted trusted npm…

  • NPM Supply Chain Attack Blueprint Evolves Web3 Fraud

    A dangerous NPM supply chain attack blueprint has surfaced, showing how cybercriminals can exploit developers and target Web3 users. Attackers compromised popular NPM packages, replacing legitimate crypto wallet addresses with their own. While the theft amounted to about $1,100, the real threat lies in the method’s potential for massive fraud. The attack demonstrates how trusted…