18 npm Packages Distribute Cross-Platform RAT to Alibaba Tool Users
Cybersecurity researchers have identified a series of malicious npm packages designed to exploit users of Alibaba developer tools, employing a ...
Cybersecurity researchers have identified a series of malicious npm packages designed to exploit users of Alibaba developer tools, employing a ...
Threat actors linked to North Korea have been discovered distributing new malicious npm packages designed to impersonate legitimate Rollup polyfill ...
Cybersecurity researchers have identified two compromised npm packages and a series of Go packages designed to deploy a Python-based information ...
As many as 144 npm packages within the Mastra namespace ("@mastra/*") have been compromised in a recent software supply chain ...
Cybersecurity researchers have revealed a malicious supply chain campaign targeting developers who utilize OpenAI Codex. The campaign exploits a tool ...
Google has attributed the recent supply chain compromise of the Axios npm package to a North Korean threat actor identified ...
In December 2025, npm implemented a significant authentication overhaul following the Sha1-Hulud incident to combat supply-chain attacks. Although this reform ...
Cybersecurity researchers have revealed a "sustained and targeted" spear-phishing campaign involving the publication of 27 malicious packages on the npm ...
A new set of four malicious packages has been identified in the npm package registry, designed to steal cryptocurrency wallet ...
Cybersecurity researchers have identified a malicious npm package named nodejs-smtp, which mimics the legitimate library nodemailer, to stealthily inject harmful ...
Copyright © 2026 News Wave
News Wave is not responsible for the content of external sites.