#NPMSecurity
The npm ecosystem powers modern web development 🌐, but it's not without risks. 🚨 Malicious libraries mimicking trusted tools can compromise projects. Stay vigilant: verify packages🛡️ #WebDev #npmSecurity

Read more at: innovirtuoso.com/technology/t...
Rising Threat of Malicious npm Libraries: A Cautionary Tale
The npm ecosystem is crucial for modern web development, but it faces risks from malicious libraries that impersonate trusted tools.
innovirtuoso.com
December 20, 2024 at 2:28 PM
This is why we can't just trust all the packages we use without checking. These attacks are happening more often, so please be careful about what you add or update in your code.
#npmsecurity #supplychainsecurity #javascript #webdev #cybersecurity
March 31, 2026 at 6:53 AM
NPM's perceived insecurity is a core theme. Its permissive package updates & install scripts are major concerns. Users suggest alternatives like pnpm/bun & stricter controls. Is Node.js viable for new projects given these risks? 🤔 #NPMsecurity 2/6
November 25, 2025 at 2:00 AM
The `postmark-mcp` backdoor highlights how easily malicious code can infiltrate through third-party packages. This specific attack underscores the constant threat of supply chain vulnerabilities in modern software development. #NPMsecurity 2/5
September 28, 2025 at 1:00 PM
Although npm has been compromised, your site is probably not affected. Read this article to help you keep calm and avoid panicking, while still keeping an eye on web security:

metadrop.net/en/articles/...

#SupplyChainAttack #npmSecurity #npmAttack
September 10, 2025 at 1:55 PM
Malicious notify-utilities v1.3.5 (npm): CRITICAL remote code execution risk. Remove from all projects now — no patch exists. Audit supply chain for compromise. More: https://radar.offseq.com/threat/mal-2026-10158-malicious-code-in-notify-utilities--b49cbdabbd7b0388 #OffSeq #npmsecurity #supplychain
MAL-2026-10158: Malicious code in notify-utilities (npm)
The notify-utilities package (version 1.3.5) impersonates the pino logger by copying its package.json description, keywords, and type definitions. Upon requiring and invoking its exported factory, it spawns a detached, unreferenced Node.js
radar.offseq.com
July 11, 2026 at 1:30 PM
Hackers compromised the npm account of Axios maintainer, releasing axios@1.14.1 and 0.30.4 with malware dropping remote access trojans on Linux, Windows, and macOS. Pin to known safe versions and rotate credentials. #OpenSource #npmSecurity #USA
Hackers compromise Axios npm package to drop cross-platform malware
Hackers hijacked the npm account for the popular Axios package and published two malicious releases that included a dependency which installs remote access trojans on Linux, Windows, and macOS. The tainted releases (axios@1.14.1 and axios@0.30.4) lacked OIDC provenance, were staged in advance with OS-specific droppers that self-destruct, and users are advised to pin to axios@1.14.0 and axios@0.30.3, rotate credentials, and rebuild from known-good states. #Axios #plain-crypto-js
www.hendryadrian.com
March 31, 2026 at 6:20 PM
npm ‘merchantprefsservice-paypal’ v28.0.0 is HIGH severity: flagged malicious for contacting suspicious domains. Remove if present. No fix available. More info: https://radar.offseq.com/threat/malicious-code-in-merchantprefsservice-paypal-npm-d57b36077d7071b9 #OffSeq #npmsecurity #ThreatIntel
Malicious code in merchantprefsservice-paypal (npm)
The 'merchantprefsservice-paypal' package at version 28.0.0 on npm is flagged as malicious due to its communication with a domain linked to malicious behavior. This classification comes from the OpenSSF Package Analysis project and is recor
radar.offseq.com
July 26, 2026 at 9:00 AM
AsyncAPI npm packages were found infected with malware that steals credentials. This impacts security for developers globally. Stay informed about safeguarding your projects. #NpmSecurity
AsyncAPI npm packages infected with credential-stealing malware
Five malicious versions of AsyncAPI packages were published to the Node Package Manager (npm) in a supply-chain attack that delivered a remote access trojan with info-stealing capabilities.
www.bleepingcomputer.com
July 16, 2026 at 10:05 AM
Malicious code in tinyparrot npm v0.4.1 (CRITICAL): Remote code execution during install via obfuscated postinstall script. Uninstall & avoid immediately. https://radar.offseq.com/threat/mal-2026-10190-malicious-code-in-tinyparrot-npm-8e0728bab742b27e #OffSeq #npmsecurity #malware
MAL-2026-10190: Malicious code in tinyparrot (npm)
The tinyparrot package version 0.4.1 includes a postinstall script (src/build.js) that reconstructs strings such as 'https', 'POST', and the destination host 'rnjkerbf.org/P' from integer-encoded arrays using base decoders in src/const.js a
radar.offseq.com
July 12, 2026 at 12:00 PM
Malicious npm packages are installing SSH backdoors, exfiltrating data from affected systems. #npmsecurity #typosquatting #supplychainattack
Rogue npm Packages Plant SSH Backdoors
Malicious npm packages are installing SSH backdoors, exfiltrating data from affected systems. #npmsecurity #typosquatting #supplychainattack
talkback.sh
April 23, 2025 at 2:14 AM
Lazarus group deploys new malware via npm packages, using advanced obfuscation. #npmsecurity #LazarusGroup #cybersecurity
Lazarus Expands npm Campaign with BeaverTail Malware
Lazarus group deploys new malware via npm packages, using advanced obfuscation. #npmsecurity #LazarusGroup #cybersecurity
securityonline.info
April 7, 2025 at 1:22 PM
North Korean Lazarus Group deploys malicious npm packages, targeting developers via typosquatting. #npmsecurity #LazarusGroup #supplychainattack
Lazarus Group Strikes NPM with Malicious Packages
North Korean Lazarus Group deploys malicious npm packages, targeting developers via typosquatting. #npmsecurity #LazarusGroup #supplychainattack
thedefendopsdiaries.com
March 12, 2025 at 5:05 PM
Malicious npm packages stole Ethereum developer keys; 1000+ downloads affected. #EthereumSecurity #NpmSecurity #SupplyChainAttack
Malicious Npm Packages Target Ethereum Developers
Malicious npm packages stole Ethereum developer keys; 1000+ downloads affected. #EthereumSecurity #NpmSecurity #SupplyChainAttack
ciso2ciso.com
January 7, 2025 at 10:24 AM
📰 Gelombang Baru Malware "Shai-Hulud" Lumpuhkan 600+ Paket npm, Targetkan Ekosistem @antv

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/05/20/gelombang-malware-shai-hulud-infeksi-600-paket-npm/

#@an
tvCompromise #berit#beritaTeknologid#claudeCodePersistencer#cyberSecuritye#npmSecurity
May 20, 2026 at 4:24 AM
NPM under attack! ⚠️

Malicious packages are exfiltrating system info via Discord. Don’t get caught off guard.

www.bleepingcomputer.com/news/securit...

#DevSecOps #NPMSecurity
Dozens of malicious packages on NPM collect host and network data
60 packages have been discovered in the NPM index that attempt to collect sensitive host and network data and send it to a Discord webhook controlled by the threat actor.
www.bleepingcomputer.com
May 26, 2025 at 2:28 AM
CanisterSprawl is a supply-chain worm spreading via compromised npm packages using stolen developer tokens to push poisoned releases and exfiltrate secrets through postinstall hooks. #npmSecurity #SupplyChain #CanisterSprawl
Self-Propagating Supply Chain Worm Hijacks npm Packages to Steal Developer Tokens
Researchers have flagged a supply-chain worm dubbed CanisterSprawl that uses compromised npm packages and stolen developer npm tokens to push poisoned releases and self-propagate via malicious postinstall hooks. The campaign exfiltrates extensive developer secrets to an HTTPS webhook and an ICP canister, includes PyPI propagation logic, and sits alongside other attacks...
www.hendryadrian.com
April 22, 2026 at 8:00 PM
Axios maintainers revealed a social engineering attack via fake Teams calls led to compromised creds and malicious npm releases (1.14.1 & 0.30.4) injecting a cross-platform RAT. Linked to North Korean threat actor UNC1069. #NorthKorea #npmSecurity
Axios npm hack used fake Teams error fix to hijack maintainer account
The Axios maintainers published a post-mortem showing a targeted social engineering campaign that led to malicious Axios npm releases (1.14.1 and 0.30.4) which injected a dependency, plain-crypto-js, that deployed a cross-platform RAT. Google TAG attributed the operation to North Korean actor UNC1069 using WAVESHAPER.V2, and maintainers have wiped affected systems, reset credentials, and advised rotating all keys. #Axios #UNC1069
www.hendryadrian.com
April 5, 2026 at 8:20 PM
Axios NPM package was compromised in a North Korean supply chain attack. Two malicious releases briefly published backdoored payloads via a staged dependency, affecting ~3% of users before removal. #NorthKorea #SupplyChain #NPMSecurity
Axios NPM Package Breached in North Korean Supply Chain Attack
A supply chain attack on the popular Axios NPM package published two backdoored releases that executed cross-platform payloads via a staged dependency and were downloaded by roughly 3% of users before removal. Security researchers attribute the operation to North Korean threat actor UNC1069, which used compromised maintainer credentials and long-lived NPM...
www.hendryadrian.com
April 1, 2026 at 12:00 PM
Attackers used compromised credentials to release malicious axios@1.14.1 and axios@0.30.4 npm packages, injecting a hidden dependency and executing a postinstall script with a Remote Access Trojan. #npmSecurity #SupplyChain #Axios
Axios supply chain attack chops away at npm trust
An attacker used compromised credentials of an Axios maintainer to publish poisoned npm packages that added a malicious dependency and executed a postinstall script to deploy a platform-specific Remote Access Trojan. Developers who ran npm install for the affected versions should treat build machines as fully compromised and rotate secrets immediately....
www.hendryadrian.com
April 1, 2026 at 2:00 AM