CyberSecurityBoardThreat Intel · CVEs · Products

Tag: npm

Cyber Products

debug npm Package

debug is a popular npm package for logging, with millions of weekly downloads. It was hijacked in September 2025 via a maintainer…

debug logging npm supply chain attack
July 30, 2026
Cyber Products

chalk npm Package

chalk is a widely used npm package for terminal string styling. It was compromised alongside debug in the September 2025 supply chain…

chalk npm supply chain attack Terminal
July 30, 2026
Cyber Products

typo-crypto npm Package

typo-crypto is a malicious npm package designed to impersonate crypto-js, first published in March 2025. It contained a trojanized file (core.js) and…

cryptocurrency malware npm typo-crypto
July 30, 2026
Cyber Products

core-js npm Package

core-js is a legitimate npm package for polyfilling JavaScript features. The malicious core.js file in typo-crypto was named to impersonate it.

core.js JavaScript npm polyfill
July 30, 2026
Cyber Products

crypto-js npm Package

crypto-js is a legitimate npm package for cryptographic functions. typo-crypto was designed to impersonate crypto-js through typosquatting.

crypto-js Cryptography npm typosquatting
July 30, 2026
Malware

DEV#POOPER: Remote Access Trojan Family

DEV#POOPER is a malware family that delivers remote access trojans (RATs) via compromised npm packages, often using blockchain-based command-and-control infrastructure.

blockchain C2 DEV#POOPER npm RAT
July 29, 2026