HeadFlash

Topic · 8 stories

npm supply chain attacks: malicious packages, news

Edited by Marcin Rybak

This edition was produced with artificial intelligence. Text and voice are generated automatically.

Timeline

  1. Malicious npm package hides loader in runtime code Security
  2. Shai-Hulud npm worm returns with identical payload, bypassing new scanning Security
  3. Hackers Abuse npm Mirrors to Host Phishing Pages on Legitimate Domains Security
  4. npm Attack Uses Provenance Attestations as Camouflage in 400+ Package Supply Chain Breach Security
  5. ChainDrop worm compromises 1,300+ npm packages Security
  6. Amazon links NPM supply chain attacks to North Korean hacker group Security
  7. Amazon Attributes Debug, Chalk, and Axios npm Attacks to North Korean Hackers Security
  8. North Korean npm Packages Impersonate Rollup Polyfill Tools Security