Flooding Dropper: Sonatype’s Tracking Name for npm Malware Campaign
Flooding Dropper is the moniker used by Sonatype for the campaign involving nearly 800 malicious npm packages. The campaign delivers cross-platform malware…
Flooding Dropper is the moniker used by Sonatype for the campaign involving nearly 800 malicious npm packages. The campaign delivers cross-platform malware…
Moika is a dependency confusion campaign observed in April that published over 250 malicious npm packages to steal environment information and deliver…
ChainDrop is an npm worm whose operators planted malicious Claude Code SessionStart hooks and VS Code folderOpen tasks in compromised repositories. The…
Cybersecurity researchers have uncovered a new evolution of the EtherHiding blockchain-based command-and-control (C2) technique, dubbed NullReceiver, which conceals the C2 server IP…
Six npm packages use the NullReceiver technique, fetching next-stage payloads via Ethereum transactions linked to North Korean threat actors, evolving from EtherHiding.
A cluster of 77 malicious extensions on the Open VSX marketplace has been discovered impersonating legitimate developer tools while exfiltrating sensitive information…
A credential-stealing npm worm that first appeared in keyv@6.0.0 has spread beyond the Keyv and Cacheable namespaces into hundreds of packages across…
Keyv is an npm package that was compromised in the August 2026 worm campaign. The malicious keyv@6.0.0 release included a preinstall script…
Pillar Security reported on August 4, 2026, that the ChainDrop npm worm planted malicious hooks in compromised repositories. The hooks trigger when…
Cybersecurity researchers have uncovered a sophisticated software supply chain attack targeting users of Alibaba developer tools with a cross-platform remote access trojan…