Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
Version 8.14.0 of the jscrambler npm package, published on July 11, 2026, shipped with a malicious preinstall hook that silently drops and…
Version 8.14.0 of the jscrambler npm package, published on July 11, 2026, shipped with a malicious preinstall hook that silently drops and…
Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm…
GitHub has officially released npm version 12, introducing significant security changes to reduce software supply chain risks. The most notable change is…
North Korean threat actors linked to the Contagious Interview campaign have published 108 unique malicious packages and browser extensions across npm, Packagist,…
Cybersecurity researchers have flagged an active browser extension campaign designed to steal cryptocurrency by stealthily replacing wallet addresses during transactions. The cryptocurrency…
VPN Go is a pair of malicious Chrome and Firefox extensions posing as free VPN tools. They contain clipboard theft logic that…
Cybersecurity researchers have flagged a new evolution of the supply chain attack linked to the Mini Shai-Hulud, Miasma, and Hades malware family,…
Attackers hijacked over 400 packages in the Arch User Repository (AUR) by adopting orphaned projects and modifying build scripts to deploy a…
Cybersecurity researchers have uncovered a network of 152 Google Chrome extensions posing as live wallpaper add-ons that distribute a potentially unwanted program…
On June 17, 2026, a software supply chain attack codenamed 'easy-day-js' compromised 145 npm packages under the @mastra/* namespace, a popular open-source…