Shai-Hulud: Historical npm Worm Activity
Shai-Hulud is a known npm worm family that has been active in past supply chain attacks. The recent ChainDrop campaign shows tradecraft…
Shai-Hulud is a known npm worm family that has been active in past supply chain attacks. The recent ChainDrop campaign shows tradecraft…
North Korean threat actors linked to the Contagious Interview campaign have published 108 unique malicious packages and browser extensions across npm, Packagist,…
Threat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that masquerade as Rollup…
PhantomRaven is a campaign that registered fake npm package names hallucinated by AI coding tools. It hid malware in 126 npm packages,…
Cybersecurity researchers have uncovered two hijacked npm packages and a cluster of Go packages designed to deploy a Python-based information stealer on…
A cluster of malicious packages that use fake .woff2 font files to conceal JavaScript payloads. Tactically overlaps with TaskJacker and PolinRider, using…
North Korean threat actors have been linked to the NullReceiver campaign, which uses trojanized npm packages to deploy malware that decodes C2…
Cybersecurity researchers have flagged a new evolution of the supply chain attack linked to the Mini Shai-Hulud, Miasma, and Hades malware family,…
Mini Shai-Hulud is a worm framework open-sourced by TeamPCP in May 2026. It was used in a campaign that poisoned npm packages…
GitHub has announced significant security changes for npm version 12, set to release next month, aimed at mitigating software supply chain attacks.…