#NPMSupplyChain
Malicious republished node-ipc npm releases 9.1.6, 9.2.3, and 12.0.1 were caught stealing developer secrets, fingerprinting hosts, and exfiltrating data via DNS TXT queries. #nodeipc #NpmSupplyChain #NodeJS
Popular node-ipc npm Package Infected with Credential Stealer
Socket detected malicious republished versions of node-ipc that steal developer secrets, fingerprint hosts, and exfiltrate data through DNS TXT queries. The incident affects node-ipc 9.1.6, 9.2.3, and 12.0.1, with historical malicious releases 10.1.1, 10.1.2, 11.0.0, and 11.1.0 tied to the 2022 compromise. #node-ipc #TekDefense #Permiso
www.hendryadrian.com
May 16, 2026 at 4:00 AM
The Injective npm backdoor hooked fromMnemonic() and stole crypto seed phrases as fake telemetry. https://intel.threadlinqs.com/threat/TL-2026-2366 #ThreatIntel #injectivesdktelemetrybackdoor #Injective #NpmSupplyChain
September 7, 2026 at 12:07 PM
Malicious npm package codexui-android posed as an OpenAI Codex web UI while stealing ~/.codex/auth.json tokens and exfiltrating them through a hidden chain tied to Android apps and API key exposure. #OpenAICodex #npmSupplyChain #AndroidApps
OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack
Researchers uncovered a malicious supply chain campaign hiding in the npm package codexui-android, which secretly steals OpenAI Codex authentication tokens from developers and sends them to sentry.anyclaw[.]store. The same exfiltration chain was also found in Android apps linked to BrutalStrike, while a separate finding showed deleted Google API keys can remain...
www.hendryadrian.com
June 1, 2026 at 12:00 PM
December 31, 2025 at 5:00 PM
A self-replicating worm named Shai-Hulud is compromising hundreds of npm packages—stealing secrets and spreading via GitHub automation. Open source trust is under siege. 🐛📦 #Worm #NPMSupplyChain
Self-Replicating Worm Compromising Hundreds of NPM Packages
An ongoing supply chain attack dubbed "Shai-Hulud" has compromised hundreds of packages in the npm repository with a self-replicating worm that steals secrets like API key, tokens, and cloud…
buff.ly
September 17, 2025 at 8:05 AM