Topic · 8 stories
npm supply chain attacks: malicious packages, news
This edition was produced with artificial intelligence. Text and voice are generated automatically.
Timeline
- Malicious npm package hides loader in runtime code Security
- Shai-Hulud npm worm returns with identical payload, bypassing new scanning Security
- Hackers Abuse npm Mirrors to Host Phishing Pages on Legitimate Domains Security
- npm Attack Uses Provenance Attestations as Camouflage in 400+ Package Supply Chain Breach Security
- ChainDrop worm compromises 1,300+ npm packages Security
- Amazon links NPM supply chain attacks to North Korean hacker group Security
- Amazon Attributes Debug, Chalk, and Axios npm Attacks to North Korean Hackers Security
- North Korean npm Packages Impersonate Rollup Polyfill Tools Security