24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages
Cybersecurity researchers at OX Security have uncovered a campaign that abuses 24 npm packages as free phishing infrastructure. The packages host HTML…
Cybersecurity researchers at OX Security have uncovered a campaign that abuses 24 npm packages as free phishing infrastructure. The packages host HTML…
A cluster of 77 malicious extensions on the Open VSX marketplace has been discovered impersonating legitimate developer tools while exfiltrating sensitive information…
Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security,…
Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm…
Software supply chain security was already complex, but the integration of AI into the build pipeline has introduced new risks that traditional…
A webinar hosted by OX researchers on July 22, 2026, covering AI integration's impact on attack surface, MCP server findings, and supply…
Cybersecurity researchers have flagged a new evolution of the supply chain attack linked to the Mini Shai-Hulud, Miasma, and Hades malware family,…
OX Security researchers identified a cluster of 24 npm packages abusing unpkg mirrors to host fake Cloudflare CAPTCHA pages. The campaign uses…
On June 17, 2026, a software supply chain attack codenamed 'easy-day-js' compromised 145 npm packages under the @mastra/* namespace, a popular open-source…