threat-intel 24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages Researchers at OX Security discovered a campaign utilizing 24 npm packages to host fake Cloudflare CAPTCHA pages via unpkg mirrors, redirecting users to phishing infrastructure. The threat actors are leveraging npm's infrastructure to deliver malware and have previously used similar techniques. The campaign initially u… The Hacker News · 5d ago High npmphishingmalware
supply-chain Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain Unit 42 research reveals a significant shift in supply chain attacks, with attackers now targeting the tools and processes developers use throughout the software development lifecycle (SDLC). The ChainDrop npm worm exemp… Palo Alto Unit 42 · Aug 21, 2026 High CVE-2024-3094supply chainnpmci/cd
threat-intel 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2 A new AI-powered Linux backdoor, RedC2 4.0, is being distributed through malicious npm packages, significantly lowering the barrier to entry for attackers. The framework, developed and sold by Red Offsec, offers advanced… The Hacker News · Aug 21, 2026 High npmlinuxbackdoor
supply-chain ChainDrop worm crawls into npm supply chain, evades standard defenses A ChainDrop worm is exploiting vulnerabilities within the npm package manager supply chain, bypassing standard security defenses. This allows attackers to inject malicious code into legitimate packages, potentially compr… The Register · Aug 15, 2026 High supply-chainnpmvulnerability
threat-intel Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer A sophisticated campaign involving nearly 800 malicious npm packages has been deployed to deliver cross-platform malware – a Remote Access Trojan (RAT) and infostealer – targeting Windows, macOS, and Linux systems. The p… The Hacker News · Aug 7, 2026 High RUnpmsupply chainmalware
threat-intel ChainDrop: Inside a Self-Propagating npm Worm A self-propagating npm worm, nicknamed ChainDrop, has infected over 400 packages, collectively downloaded hundreds of millions of times weekly. Developed by a threat actor, the worm steals sensitive data including cloud… Palo Alto Unit 42 · Aug 6, 2026 High npmgithubcredential theft
threat-intel Token Jacking: Cybercriminals Could Be Stealing Your AI Resources Cybercriminals are exploiting a growing trend of AI token jacking to generate significant financial losses. As AI adoption increases and costs for accessing powerful models rise, attackers are stealing API keys – known a… Palo Alto Unit 42 · Aug 6, 2026 High CHaitoken jackingtransfer station
supply-chain Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th) A sophisticated supply-chain attack leveraging compromised npm packages (keyv and cacheable) has been active since August 4th, 2026. Attackers exploited a vulnerability to inject malicious code into widely used libraries… SANS Internet Storm Center · Aug 5, 2026 High supply-chainnpmcredential theft
threat-intel Trojanized npm Packages Decode C2 IP From Ethereum Recipient Addresses North Korean hackers are utilizing a new, more sophisticated command-and-control (C2) technique called NullReceiver to evade detection. Instead of embedding a C2 address in a transaction or using a smart contract, NullRe… The Hacker News · Aug 5, 2026 High KPc2ethereumnpm
supply-chain Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack A sophisticated supply chain attack, dubbed ChainDrop, has infected over 2,200 malicious versions of 440 NPM packages, resulting in over 500 million weekly downloads. The attack began with a compromised GitHub account an… SecurityWeek · Aug 5, 2026 High supply chainnpmgithub
threat-intel Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks A sophisticated npm worm, linked to the Keyv vulnerability and attributed to the Shai-Hulud threat actor family, has spread across hundreds of packages, injecting credential-stealing and malicious code. The worm leverage… The Hacker News · Aug 4, 2026 High npmsupply-chaincredential-stealing
threat-intel 18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users A sophisticated supply chain attack targeting Chinese-speaking developers using Alibaba tools has been discovered. Researchers found a set of malicious npm packages, including wrappers mimicking private Alibaba packages,… The Hacker News · Aug 3, 2026 High CHsupply chainmalwarenpm
threat-intel Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet Amazon has attributed the September 2025 compromise of npm packages debug and chalk, along with subsequent incidents involving typo-crypto and axios, to North Korea’s Sapphire Sleet group. While initial reports attribute… The Hacker News · Jul 30, 2026 High KPnpmthreat intelligencemalware
threat-intel Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js Two compromised npm packages within the @joyfill namespace have been injected with a remote access trojan (RAT) linked to the DEV#POPPER malware family. These packages utilize a complex blockchain-based infrastructure (T… The Hacker News · Jul 29, 2026 High KPnpmmalwareremote access trojan
supply-chain Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT A sophisticated software supply chain attack, dubbed ViteVenom, is leveraging a blockchain-based command-and-control (C2) infrastructure to deliver a remote access trojan (RAT) targeting Vite frontend developers. The att… The Hacker News · Jul 17, 2026 High supply chainblockchainc2
supply-chain The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) The npm ecosystem experienced a critical inflection point in September 2025 with the emergence of the Shai-Hulud worm, marking a shift from nuisance attacks to a high-consequence threat landscape. Since then, Unit 42 has… Palo Alto Unit 42 · Jul 15, 2026 High NLsupply chainnpmgithub
supply-chain Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware A sophisticated supply-chain attack leveraging compromised npm packages has delivered a multi-stage botnet loader, Miasma, to numerous developers. The attacker exploited a GitHub Actions release pipeline to inject malici… The Hacker News · Jul 15, 2026 High supply chainnpmgithub actions
supply-chain Multiple Jscrambler Packages Impacted by Supply Chain Attack A supply chain attack targeting Jscrambler’s NPM package led to the distribution of malicious versions containing malware designed to steal sensitive information from developer and cloud environments. The attack exploite… SecurityWeek · Jul 14, 2026 High npmsupply chainmalware
threat-intel 148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet A campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service botnet for roughly two weeks in May. These packages, initially designed as tutoring tools, lo… The Hacker News · Jul 14, 2026 High USbotnetddosproxy
supply-chain Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install A malicious npm package, jscrambler 8.14.0, was released with a hidden infostealer that silently dropped and executed during installation. The package, pushed by a compromised account, included a Rust-based stealer targe… The Hacker News · Jul 11, 2026 High npmsupply-chainrust