News

JavaScript packages with billions of downloads were compromised by an unknown threat actor looking to steal cryptocurrency.
On September 8, 2025, a single phishing email triggered one of npm’s most damaging supply chain attacks, compromising 18 ...
Binance reassures customers after a massive NPM supply chain attack injects malicious code into 18 popular JavaScript ...