#MaliciousPackages
Seven Malicious NPM Packages Use Adspect to Redirect to Crypto Scams

#Adspect #cryptoscams #JavaScript #maliciouspackages #NPM
Seven Malicious NPM Packages Use Adspect to Redirect to Crypto Scams
Cybersecurity researchers have uncovered seven malicious JavaScript packages on NPM that utilize Adspect, a commercial cloaking service. These packages are
blazetrends.com
November 19, 2025 at 12:11 AM
March 25, 2026 at 4:01 PM
December 31, 2025 at 5:00 PM
#PhantomRaven is back 👻🐦‍⬛ We found 3 new waves distributing 88 #maliciouspackages (81 still live on npm). Packages look clean, but a hidden URL in package.json pulls credential-stealing malware.
www.endorlabs.com/learn/return...
The Return of PhantomRaven: Detecting Three New Waves of npm Supply Chain Attacks | Blog | Endor Labs
Endor Labs security researchers identified 88 malicious open source packages belonging to three new waves of the PhantomRaven campaign.
www.endorlabs.com
March 11, 2026 at 4:48 PM
In that article, Darren lays out the problem as well as a strategy for putting controls in place that make your developers' lives easier while adding significant protection against the risk of #maliciousPackages through well-designed controls and lightweight policies
February 19, 2026 at 2:37 PM
And of course, as always, we appreciate the support of Microsoft and OpenVSX, both of whom responded promptly and professionally.

#SupplyChainSecurity #MaliciousPackages #DeveloperSecurity #SoftwareSupplyChain #ExtensionSecurity #VisualStudioCode
December 5, 2025 at 4:04 PM
MPIAPI users blocking identified malware will already have these packages stopped.
This campaign shows no sign of slowing. Share awareness and keep dependencies clean.

#CyberSecurity #DevSecOps #NorthKorea #MaliciousPackages 🧵6/6
November 12, 2025 at 10:08 PM
July 4, 2026 at 5:16 PM