#npmattack
Shai-Hulud Attack Escalates: CrowdStrike NPM Packages Compromised
www.cyberkendra.com/2025/09/shai...
#npmattack #cybersecurity #infosec #crowdstrike
Shai-Hulud Attack Escalates: CrowdStrike NPM Packages Compromised
Another wave of NPM Hack.
www.cyberkendra.com
September 17, 2025 at 11:07 PM
Although npm has been compromised, your site is probably not affected. Read this article to help you keep calm and avoid panicking, while still keeping an eye on web security:

metadrop.net/en/articles/...

#SupplyChainAttack #npmSecurity #npmAttack
September 10, 2025 at 1:55 PM
Also, npm now supports trusted publishing: https://docs.npmjs.com/trusted-publishers

This means you don't need a static token in your CI/CD configuration anymore.

#npm #npmattack
Trusted publishing for npm packages | npm Docs
Documentation for the npm registry, website, and command-line interface
docs.npmjs.com
September 8, 2025 at 7:13 PM
🚨 TanStack npm attack exposed supply‑chain risks: poisoned packages harvested cloud & developer credentials within minutes before being pulled.

🌐 spoofguard.io/blog/en/doma...

#TanStack #npmattack #SupplyChainSecurity #CredentialHarvesting #CyberThreats

Try it for FREE. 🆓
Domain Spoofing Protection After the TanStack npm Attack | Spoofguard.io
✓ Domain spoofing protection helps detect impersonation risks after a TanStack npm supply-chain attack exposed how developer credentials can become a threat.
spoofguard.io
September 1, 2026 at 10:43 AM
NPM Attack on Core JavaScript Libraries Puts Millions of Crypto Users at Risk

#NPMAttack #javascript
chainaffairs.com/npm-attack-o...
NPM Attack on Core JavaScript Libraries Puts Millions of Crypto Users at Risk -
A massive security breach has rocked the open-source ecosystem after hackers compromised widely used JavaScript libraries
chainaffairs.com
September 8, 2025 at 7:41 PM
🔥 The NPM supply chain attack just got bigger!
DuckDB database packages have been compromised with crypto-stealing malware. A simple phishing email led to packages used by thousands of developers being infected.
www.cyberkendra.com/2025/09/duck...

#supplychain #npmPackage #npmattack #hack
DuckDB Packages Compromised in Latest NPM Supply Chain Attack
NPM Supply Chain Massive Security Breach
www.cyberkendra.com
September 9, 2025 at 5:35 PM
A new npm supply-chain attack targets multiple Namastex Labs packages, stealing developer tokens and secrets while self-propagating across npm and PyPI ecosystems. Cross-ecosystem threats grow. #NamastexLabs #npmAttack #SupplyChain
New npm supply-chain attack self-spreads to steal auth tokens
A new supply chain attack targeting the npm ecosystem has compromised multiple Namastex Labs packages to steal developer credentials and secrets while attempting to self-propagate. Researchers from Socket and StepSecurity observed credential theft, data exfiltration, and worm-like republishing behavior similar to TeamPCP's CanisterWorm, impacting packages such as pgserve and allowing cross-ecosystem spread to PyPI. #NamastexLabs #npm #CanisterWorm #pgserve #PyPI
www.hendryadrian.com
April 22, 2026 at 4:15 PM
A proof-of-concept AI-driven supply-chain monitor detected a malicious npm compromise in Axios, linked to a broader campaign by TeamPCP involving phantom dependencies and postinstall hooks deploying cross-platform malware. #SupplyChain #npmAttack
How we caught the Axios supply chain attack
The author built a proof-of-concept AI-driven monitor that diffs package releases and flagged a malicious npm compromise of Axios that used a phantom dependency with a postinstall hook to deploy cross-platform malware. The incident ties into a wider supply-chain campaign (Trivy → LiteLLM → Telnyx → Axios) attributed to TeamPCP, prompting coordinated detection, takedown, and recommendations for registry monitoring and release soak times. #Axios #TeamPCP
www.hendryadrian.com
April 2, 2026 at 8:40 PM
A supply chain attack compromised Axios npm releases (1.14.1 & 0.30.4) by injecting plain-crypto-js@4.2.1, a trojanized dependency delivering macOS RAT with data collection and command execution. #SupplyChain #npmAttack #USA
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
Attackers published compromised Axios releases (axios@1.14.1 and axios@0.30.4) that introduced a trojanized dependency plain-crypto-js@4.2.1, which uses a postinstall dropper to deliver platform-specific payloads and a macOS Mach-O RAT capable of command execution, data collection, and persistence. Socket and other researchers tracked the C2 to sfrclak[.]com, identified additional tainted packages and vendor chains, and have recommended revoking tokens, checking lockfiles, and rolling back affected versions. #Axios #plain-crypto-js
www.hendryadrian.com
April 1, 2026 at 6:00 PM
On March 31, 2026, attacker hijacked axios npm maintainer account to publish malicious versions 1.14.1 and 0.30.4 adding typosquatted dependency plain-crypto-js that deployed a cross-platform RAT during install. #npmAttack #CrossPlatform #USA
Compromised axios npm package delivers cross-platform RAT
On March 31, 2026, an attacker hijacked an axios npm maintainer account and published malicious releases (axios@1.14.1 and 0.30.4) that added a typosquatted dependency plain-crypto-js which executed a cross-platform RAT during npm install. The compromise was active for about three hours before npm removed the packages; the RAT communicated with C2 sfrclak[.]com and delivered macOS, Windows, and Linux payloads (all containing bugs), while maintainers and npm revoked tokens and mitigations followed. #axios #plain-crypto-js
www.hendryadrian.com
March 31, 2026 at 10:20 PM
CanisterWorm campaign compromises 29+ npm packages across @emilgroup and @teale.io namespaces, deploying a Python backdoor that fetches second-stage payloads via ICP canisters. Uses npm tokens and postinstall hooks. #SupplyChain #NPMAttack
CanisterWorm: npm Publisher Compromise Deploys Backdoor Across 29+ Packages
Socket’s Threat Research Team uncovered a worm-enabled npm supply chain attack that compromised legitimate publisher namespaces including @emilgroup and @teale.io, replacing package contents with a Python implant that polls an ICP canister for rotatable second-stage payloads. The campaign, dubbed CanisterWorm, uses postinstall hooks, a systemd --user persistent service named pgmon, and a deploy.js republishing worm that leverages npm publishing tokens (often published with --tag latest) to propagate. #CanisterWorm #EmilGroup
www.hendryadrian.com
March 21, 2026 at 3:40 PM
AIMindUpdate News!
Critical alert! Popular JavaScript packages were compromised in a supply chain attack, exposing users to backdoor malware. #NPMattack #SupplyChainSecurity #JavaScriptMalware

Click here↓↓↓
aimindupdate.com/2025/07/26/n...
NPM Supply Chain Attack: Backdoor Malware Spreading | AI News
JavaScript packages compromised! Learn about the NPM supply chain attack and how it exposed users to backdoor malware.
aimindupdate.com
July 26, 2025 at 5:30 AM
⚠️حذّر Charles Guillemet، كبير تقنيي Ledger، من هجوم بدأ باختراق حساب NPM لمطوّر موثوق، أدخل شيفرة خبيثة تُبدّل عناوين محافظ التشفير تلقائيًا في المتصفح، ما يعرض الأموال للخطر دون علم المستخدمين. تأكّد يدويًا من العناوين قبل الموافقة. #Crypto #Security #Ledger #NPMAttack
September 9, 2025 at 10:29 AM
Pro-tip for npm: rather than using a classic access token in your ~/.npmrc file, generate a granular access token that only has read permissions.

That way if something does compromise you, they only get access to the read token and cannot publish on your behalf.

#npm #npmattack
September 8, 2025 at 7:09 PM
Shai-Hulud Attack Escalates: ClownStrike NPM Packages Compromised
www.potatokendra.com/2025/09/shai...
#npmattack #potatosecurity #infosec #clownstrike
September 17, 2025 at 11:07 PM