A new malware campaign has been observed built on seven npm packages and using cloaking techniques and fake CAPTCHAs, ...
Cybersecurity researchers have discovered a set of seven npm packages published by a single threat actor that leverages a ...
Seven packages published on the Node Package Manager (npm) registry use the Adspect cloud-based service to separate ...
More than 150,000 malicious packages were published in the NPM registry as part of a recently uncovered spam campaign, Amazon ...
The coordinated campaign has so far published as many as 46,484 packages, according to SourceCodeRED security researcher Paul ...
A recent supply chain malware attack affected popular NPM packages, potentially reaching millions of downloads in just a few ...
Over 150,000 npm packages linked to a TEA token farming scheme were flagged by Amazon InspectorAttackers used ...
Yet another supply chain attack has hit the npm registry in what Amazon describes as "one of the largest package flooding ...
Malware Injected Into Code Packages That Get 2 Billion+ Downloads Each Week Your email has been sent An attack targeting the Node.js ecosystem was just identified ...
“After GlassWorm showed how quickly a malicious package could self-replicate across npm, and the chalk/debug hijacking ...
A threat actor has published tens of thousands of malicious NPM packages that contain a self-replicating worm, security ...