CyberSecurityBoardThreat Intel · CVEs · Products

Tag: npm

Malware

MYRA: Linux Remote Access Trojan

MYRA is a full-featured Linux RAT delivered via a malicious npm package 'apintergrationpost', claiming to be a Node.js integration client for red…

fileless execution Linux MYRA npm
June 25, 2026
Cyber Companies

SafeDep: npm Supply Chain Research

SafeDep is a cybersecurity company that identified two npm supply chain campaigns: one typosquatting CLI binary names and another involving malicious Baileys…

npm research SafeDep Supply Chain
June 25, 2026
Cyber Products

PostCSS: CSS Processing Tool

PostCSS is a legitimate CSS processing tool with millions of weekly npm downloads, which was impersonated by malicious packages to deliver malware.

CSS npm PostCSS Supply Chain
June 25, 2026
Cyber Products

npm Packages Poisoned by TeamPCP

npm was one of the ecosystems targeted by TeamPCP. Malicious packages like keyv and cacheable were poisoned in August 2026.

npm package manager Supply Chain
June 25, 2026
Cyber Companies

Socket Analyzes TeamPCP npm Wave

Socket analyzed the fresh npm wave using the Mini Shai-Hulud toolkit, but could not recover self-identifying markers to tie the sample to…

malware npm research Socket
June 25, 2026