Cybersecurity researchers have uncovered a typosquatting campaign targeting RubyGems users with a Windows-based information stealer. The campaign, tracked as StubMaker by OpenSourceMalware,…
Cybersecurity researchers have uncovered a sophisticated software supply chain attack targeting users of Alibaba developer tools with a cross-platform remote access trojan…
AlibabaAlibaba GroupbackdoorChinese-speaking threat actor
Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security,…
A campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service (DDoS) botnet for roughly…
On June 17, 2026, a software supply chain attack codenamed 'easy-day-js' compromised 145 npm packages under the @mastra/* namespace, a popular open-source…
Cybersecurity researchers at JFrog have uncovered a set of malicious npm packages that masquerade as legitimate PostCSS tools to deliver a Windows-based…
SafeDep is a cybersecurity company that identified two npm supply chain campaigns: one typosquatting CLI binary names and another involving malicious Baileys…