atomic-lockfile@1.4.2: Malicious npm Package
The npm package atomic-lockfile@1.4.2 was used in the Atomic Arch campaign to deliver the deps payload via a preinstall hook. It was…
The npm package atomic-lockfile@1.4.2 was used in the Atomic Arch campaign to deliver the deps payload via a preinstall hook. It was…
The npm package js-digest was used in a second wave of the Atomic Arch attack, delivered via bun install. It contained a…
Sonatype identified six npm packages using Ethereum transactions to fetch malware, a technique called NullReceiver linked to North Korean actors.
Attackers hijacked over 400 packages in the Arch User Repository (AUR) by adopting orphaned projects and modifying build scripts to deploy a…
Cybersecurity researchers have uncovered two malicious campaigns linked to North Korean threat actors, exploiting developer tools like Microsoft Visual Studio Code (VS…
A cross-platform information stealer deployed as the final payload in the Mastra supply chain attack. It harvests browser history, steals data from…
OX Security researchers identified a cluster of 24 npm packages abusing unpkg mirrors to host fake Cloudflare CAPTCHA pages. The campaign uses…
Mastra is an open-source JavaScript and TypeScript framework for building AI applications. In June 2026, 145 of its npm packages were compromised…
axios is a popular npm package for making HTTP requests. It was compromised in March 2026 by Sapphire Sleet/UNC1069 via a post-install…
On June 17, 2026, a software supply chain attack codenamed 'easy-day-js' compromised 145 npm packages under the @mastra/* namespace, a popular open-source…