debug npm Package
debug is a popular npm package for logging, with millions of weekly downloads. It was hijacked in September 2025 via a maintainer…
debug is a popular npm package for logging, with millions of weekly downloads. It was hijacked in September 2025 via a maintainer…
chalk is a widely used npm package for terminal string styling. It was compromised alongside debug in the September 2025 supply chain…
Two npm packages in the @joyfill namespace, @joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4, have been compromised to deliver a remote access trojan (RAT) associated with…
Cybersecurity researchers have uncovered a large-scale campaign that weaponizes compromised GitHub repositories to target cPanel and WebHost Manager (WHM) instances. The activity…
Water Curse is a threat cluster tracked by Trend Micro that operates a GitHub-based ghost network to redirect users to malware-laced payloads.…
Cybersecurity researchers at JFrog have uncovered a sophisticated NuGet typosquatting campaign targeting the popular Newtonsoft.Json library. The malicious package, named "Newtonsoftt.Json.Net," is…
A trojanized fork of the Newtonsoft.Json library, published as 'Newtonsoftt.Json.Net' on NuGet, designed to rig live game results on the Digitain betting…
Digitain is the operator of the FG-Crash betting game, which was the primary target of the Newtonsoftt.Json.Net typosquat attack. The company has…
Cybersecurity researchers have uncovered a large-scale campaign dubbed FakeGit, which leverages nearly 7,600 malicious GitHub repositories to distribute the SmartLoader malware. The…
Cybersecurity researchers have uncovered a sophisticated software supply chain attack dubbed 'SleeperGem' targeting the Ruby ecosystem. Three malicious gems were published to…