TanStack has released a detailed postmortem describing a sophisticated supply-chain attack that compromised 42 npm packages ...
In a surprising move, the popular open source project, SheetJS aka "xlsx," has dropped support for the npm registry. Downloaded about 1.4 million times weekly on npm, SheetJS is relied upon by NodeJS ...
GitHub's npm package registry has rolled out a publishing approval step to prevent the distribution of compromised packages ...
A new set of 16 malicious NPM packages are pretending to be internet speed testers but are, in reality, coinminers that hijack the compromised computer's resources to mine cryptocurrency for the ...
Four packages containing highly obfuscated malicious Python and JavaScript code were discovered this week in the Node Package Manager (npm) repository. According to a report from Kaspersky, the ...
If you needed another reminder that our software supply chains are only as strong as their smallest link, the JavaScript ecosystem delivered it. In early September, attackers phished the NPM account ...
Sometime around the last week of May 2026, attackers uploaded poisoned packages to three of the most widely used software ...
Researchers continue to investigate a wave of malicious npm packages, with the published tally now reaching over 700. Last week, JFrog researchers disclosed the scheme in which an unknown threat actor ...
The malware authors behind the npm worm Shai-Hulud have released the source code. Now the first clones are appearing.