vulnerability Multiples vulnérabilités dans Node.js (30 juillet 2026) Multiple vulnerabilities have been discovered in Node.js, impacting versions 22.x, 24.x, and 26.x prior to the specified release dates. These vulnerabilities can lead to data integrity compromise, data confidentiality issues, and denial-of-service attacks. Users are advised to consult the Node.js security bulletin for… CERT-FR · Jul 30, 2026 Medium CVE-2026-48934CVE-2026-56846CVE-2026-56847nodejsvulnerabilitysecurity
threat-intel Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js Two compromised npm packages within the @joyfill namespace have been injected with a remote access trojan (RAT) linked to the DEV#POPPER malware family. These packages utilize a complex blockchain-based infrastructure (T… The Hacker News · Jul 29, 2026 High KPnpmmalwareremote access trojan
threat-intel 20+ Hijacked Government Websites Became an Attack Channel A sophisticated campaign, dubbed PhantomEnigma, has hijacked over 20 Brazilian government websites to deliver malware and conduct attacks against banks and public agencies. Attackers leveraged compromised .gov.br infrast… The Hacker News · Jul 16, 2026 High BRgovernmentphishingmalware
threat-intel Phishers Gain Persistence at EU, Asia Hospitality Orgs Phishing campaigns targeting hospitality organizations in Europe and Asia are utilizing malicious zip files containing disguised image files to install persistent malware. These attacks, observed by Microsoft and Trend M… Dark Reading · Jun 30, 2026 High GBJPphishingpersistencesocial engineering
threat-intel Microsoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js Implant A phishing campaign targeting hotels and hospitality organizations is underway, utilizing deceptive ZIP files containing Node.js implants to gain access to front-desk machines. The campaign, discovered by Microsoft, empl… The Hacker News · Jun 26, 2026 High GBJPDKphishingnode.jston
malware Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT A series of malicious npm packages, disguised as PostCSS tools, have been discovered delivering a Windows-based remote access trojan (RAT). These packages, published by 'abdrizak', leveraged legitimate build tooling to d… The Hacker News · Jun 23, 2026 High USnpmsupply-chainrat
supply-chain Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer A new supply chain attack, dubbed Hades, is leveraging the Miasma campaign to compromise 37 PyPI packages, including those used in bioinformatics and computational biology. The attack utilizes a malicious setup.pth file… The Hacker News · Jun 9, 2026 High RUsupply-chainpythoncredential-stealing
supply-chain 'Hades' Campaign Against PyPI Puts New Spin on Shai-Hulud A new wave of attacks, dubbed the 'Hades' campaign, has targeted the Python Package Index (PyPI) with a variant of the Shai-Hulud worm. This campaign involved compromising 37 PyPI wheels and 19 code packages, utilizing a… Dark Reading · Jun 8, 2026 High USsupply-chainpythonopen-source
malware Cross-Platform NPM Stealer, (Fri, May 22nd) A cross-platform Node.js stealer has been discovered targeting Windows, macOS, and Linux systems. The malware, obfuscated to avoid detection, extracts sensitive data from various browsers and applications, including Chro… SANS Internet Storm Center · May 22, 2026 High USstealerobfuscatedbrowser
threat-intel Developer Workstations Are Now Part of the Software Supply Chain Recent attacks, including those mimicking the "mini Shai Hulud" and "Shai-Hulud 2.0" campaigns, have highlighted a growing threat: attackers targeting developer workstations to steal credentials and secrets from CI/CD pi… The Hacker News · May 18, 2026 High USdeveloper workstationssecretssupply chain