A reported compromise in the Jscrambler package shows how install-time code can turn developer machines and CI pipelines into high-value targets for cloud and wallet secrets.
A poisoned-package wave tied to Mini Shai-Hulud, Miasma, and Hades is pushing supply-chain risk into the heart of developer workstations and CI/CD pipelines.
A supply-chain lure inside package install and build steps can turn routine development work into an execution window for credential theft, especially when teams trust native-addon metadata too quickly.
A hijacked maintainer path, a typosquat package, and two very different payloads show how supply-chain abuse can reach far beyond one namespace.
Researchers say dozens of Red Hat npm packages were targeted, a reminder that package trust and install-time execution can turn one bad release into a wider security problem.
A malicious Codex UI package in npm was reported to have stolen OpenAI refresh tokens, a reminder that developer tooling can turn into a credential-harvesting channel with account-takeover consequences.
A sprawling npm supply-chain incident shows how a single publishing path can ripple through developer tooling, while provenance metadata may look reassuring even when it is part of the problem.
A reported compromise inside the @antv package ecosystem shows how one account can become a publishing choke point for downstream JavaScript projects.
Malicious node-ipc releases on npm show how one bad publish can turn dependency management into a security boundary, especially when build systems and developer tools are in the blast radius.
A fresh wave of compromise in the npm ecosystem shows how a single malicious package can cross from developer laptops into CI/CD pipelines, where credentials and publishing access become the real prize.
An ongoing compromise of 84 npm packages in the TanStack ecosystem shows how a poisoned dependency can turn automated builds into a high-value target for credential theft.
A fresh supply-chain wave involving hundreds of malicious package versions shows how quickly routine dependency installs can turn into an enterprise risk.
A large-scale supply-chain incident in the npm ecosystem shows how a malicious package can look ordinary when the build and publish pipeline itself has been bent out of shape.
A new wave of npm supply-chain attacks targets developers with hidden credential stealers and a stealthy remote access trojan.