Sunday 26 July 2026 11:22:22 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

#npm supply-chain


When a Trusted npm Package Becomes a Secret Hunter

Published: 13 July 2026 10:26Category: CybercrimeGeo: Europe / PortugalAuthor: CIPHERWARDEN

A reported compromise in the Jscrambler package shows how install-time code can turn developer machines and CI pipelines into high-value targets for cloud and wallet secrets.

Trusted npm Packages Become the Doorway in a Quiet Secret-Harvesting Campaign

Published: 26 June 2026 08:03Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A poisoned-package wave tied to Mini Shai-Hulud, Miasma, and Hades is pushing supply-chain risk into the heart of developer workstations and CI/CD pipelines.

Npm’s Hidden Trapdoor: How Malicious Packages Can Exploit node-gyp to Target Developer Secrets

Published: 25 June 2026 12:07Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

A supply-chain lure inside package install and build steps can turn routine development work into an execution window for credential theft, especially when teams trust native-addon metadata too quickly.

When a Trusted Package Turns Toxic: The Mastra npm Intrusion

Published: 22 June 2026 10:12Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

A hijacked maintainer path, a typosquat package, and two very different payloads show how supply-chain abuse can reach far beyond one namespace.

Red Hat Named in an npm Supply-Chain Probe as Mini Shai-Hulud Returns to the Spotlight

Published: 02 June 2026 18:09Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

Researchers say dozens of Red Hat npm packages were targeted, a reminder that package trust and install-time execution can turn one bad release into a wider security problem.

A Small NPM Helper, a Big Identity Leak: How Refresh Tokens Become the Prize

Published: 31 May 2026 18:03Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

A malicious Codex UI package in npm was reported to have stolen OpenAI refresh tokens, a reminder that developer tooling can turn into a credential-harvesting channel with account-takeover consequences.

When Package Trust Becomes the Attack Surface

Published: 20 May 2026 10:32Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A sprawling npm supply-chain incident shows how a single publishing path can ripple through developer tooling, while provenance metadata may look reassuring even when it is part of the problem.

When a Maintainer Login Becomes a Delivery Weapon in npm

Published: 19 May 2026 10:44Category: Malware & BotnetsGeo: Asia / ChinaAuthor: NEXUSGUARDIAN

A reported compromise inside the @antv package ecosystem shows how one account can become a publishing choke point for downstream JavaScript projects.

When a Trusted npm Package Turns into a Silent Secret Hunter

Published: 15 May 2026 08:09Category: Malware & BotnetsAuthor: NEXUSGUARDIAN

Malicious node-ipc releases on npm show how one bad publish can turn dependency management into a security boundary, especially when build systems and developer tools are in the blast radius.

The npm Trust Trap: A Worm-Like Campaign Turns Ordinary Updates into Secret Theft

Published: 12 May 2026 19:47Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A fresh wave of compromise in the npm ecosystem shows how a single malicious package can cross from developer laptops into CI/CD pipelines, where credentials and publishing access become the real prize.

When Build Pipelines Become Bait: The TanStack npm Incident and the Secret Hunt Inside CI

Published: 12 May 2026 17:57Category: CybercrimeGeo: North America / USAAuthor: CRYSTALPROXY

An ongoing compromise of 84 npm packages in the TanStack ecosystem shows how a poisoned dependency can turn automated builds into a high-value target for credential theft.

Poisoned Packages, Fragile Trust: Mini Shai-Hulud Pushes npm Security Back Into the Spotlight

Published: 12 May 2026 14:16Category: Malware & BotnetsAuthor: IRONQUERY

A fresh supply-chain wave involving hundreds of malicious package versions shows how quickly routine dependency installs can turn into an enterprise risk.

When a Package Turns Predatory: The Shai-Hulud npm Wave and the Collapse of Build Trust

Published: 12 May 2026 13:42Category: Malware & BotnetsAuthor: IRONQUERY

A large-scale supply-chain incident in the npm ecosystem shows how a malicious package can look ordinary when the build and publish pipeline itself has been bent out of shape.

Steganography and Subterfuge: North Korean Hackers Infiltrate JavaScript Ecosystem via npm Trap

Published: 03 March 2026 14:37Category: Cyber Intelligence & Threat TrendsGeo: AsiaAuthor: SECPULSE

A new wave of npm supply-chain attacks targets developers with hidden credential stealers and a stealthy remote access trojan.