Sapphire Sleet: North Korean Threat Actor Behind Supply Chain Attacks
Microsoft assesses with high confidence that the Mastra npm compromise is attributable to Sapphire Sleet, a North Korean threat actor known for…
Microsoft assesses with high confidence that the Mastra npm compromise is attributable to Sapphire Sleet, a North Korean threat actor known for…
easy-day-js is a malicious npm package that cloned the legitimate 'dayjs' date library. Published by user 'sergey2016', it initially appeared clean but…
Cybersecurity researchers at JFrog have uncovered a set of malicious npm packages that masquerade as legitimate PostCSS tools to deliver a Windows-based…
MYRA is a full-featured Linux RAT delivered via a malicious npm package 'apintergrationpost', claiming to be a Node.js integration client for red…
SafeDep is a cybersecurity company that identified two npm supply chain campaigns: one typosquatting CLI binary names and another involving malicious Baileys…
PostCSS is a legitimate CSS processing tool with millions of weekly npm downloads, which was impersonated by malicious packages to deliver malware.
npm was one of the ecosystems targeted by TeamPCP. Malicious packages like keyv and cacheable were poisoned in August 2026.
Socket analyzed the fresh npm wave using the Mini Shai-Hulud toolkit, but could not recover self-identifying markers to tie the sample to…