GitHub Introduces 3-Day Dependabot Cooldown to Mitigate Poisoned Package Attacks
GitHub has announced a new cooldown mechanism for Dependabot that introduces a mandatory three-day waiting period before opening pull requests for version…
GitHub has announced a new cooldown mechanism for Dependabot that introduces a mandatory three-day waiting period before opening pull requests for version…
Cybersecurity researchers at Checkmarx have uncovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of…
ViteVenom is a malware campaign discovered by Checkmarx that uses seven malicious scoped npm packages to deliver a RAT via blockchain-based C2…
ChainVeil is a previous malware campaign that used unscoped typosquat npm packages and a four-tier blockchain C2 infrastructure to deliver a remote…
Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security,…
A campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service (DDoS) botnet for roughly…
A self-replicating worm that hit more than 500 npm packages in September 2025, harvesting developer secrets and republishing itself with stolen tokens.
Version 8.14.0 of the jscrambler npm package, published on July 11, 2026, shipped with a malicious preinstall hook that silently drops and…
Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm…
GitHub has officially released npm version 12, introducing significant security changes to reduce software supply chain risks. The most notable change is…