Ethereum and Solana developers were targeted by five malicious npm packages that steal private keys and send them to the ...
After hacking Trivy, TeamPCP moved to compromise repositories across NPM, Docker Hub, VS Code, and PyPI, stealing over 300GB ...
CanisterWorm infects 28 npm packages via ICP-based C2, enabling self-propagation and persistent backdoor access across ...
A new malicious npm campaign using fake installation logs to hide malware activity has been identified by security ...
UTC, Aikido Security detected an unusual pattern across the npm registry: dozens of packages from multiple organizations were ...
In March, JFrog Security Research documented a malware campaign titled GhostClaw/GhostLoader. Since the original ...
The GlassWorm supply-chain campaign has returned with a new, coordinated attack that targeted hundreds of packages, ...