CyberSecurityBoardThreat Intel · CVEs · Products
Malware

atomic-lockfile@1.4.2: Malicious npm Package

June 25, 2026

The npm package atomic-lockfile@1.4.2 was used in the Atomic Arch campaign to deliver the deps payload via a preinstall hook. It was pulled from the npm registry after discovery.