Alibaba Group Targeted in Supply Chain Attack
Alibaba Group's developer tools were targeted in a software supply chain attack via malicious npm packages impersonating private @ali-scoped packages. The attack…
Alibaba Group's developer tools were targeted in a software supply chain attack via malicious npm packages impersonating private @ali-scoped packages. The attack…
Amazon Threat Intelligence has attributed the September 2025 hijack of the popular npm packages debug and chalk to North Korea's Sapphire Sleet…
Aikido is a security platform that reported at least 868 packages affected by the npm worm and linked the campaign to the…
debug is a popular npm package for logging, with millions of weekly downloads. It was hijacked in September 2025 via a maintainer…
chalk is a widely used npm package for terminal string styling. It was compromised alongside debug in the September 2025 supply chain…
typo-crypto is a malicious npm package designed to impersonate crypto-js, first published in March 2025. It contained a trojanized file (core.js) and…
core-js is a legitimate npm package for polyfilling JavaScript features. The malicious core.js file in typo-crypto was named to impersonate it.
crypto-js is a legitimate npm package for cryptographic functions. typo-crypto was designed to impersonate crypto-js through typosquatting.
DEV#POOPER is a malware family that delivers remote access trojans (RATs) via compromised npm packages, often using blockchain-based command-and-control infrastructure.
Two npm packages in the @joyfill namespace, @joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4, have been compromised to deliver a remote access trojan (RAT) associated with…