News

Threat actors injected malicious code into multiple popular NPM packages after their maintainers fell for a well-crafted ...
A cryptocurrency thief got into the npm account of a hard-working developer via spearphishing. node.js packages with billions ...
Hackers planted malicious code in open source software packages with more than 2 billion weekly updates in what is likely to ...
Billions (No, that's not a typo, Billions with a capital B) of files were potentially compromised. If you thought Node Package Manager (npm), the Billions of downloads were potentially compromised ...
The credential stealer harvested username, password, and 2FA codes before sending them to a remote host. With full access, ...
Qix is an open source maintainer account that was compromised by a phishing attack. This allowed attackers to infect 18 popular npm packages with malicious code. Together, these packages are ...
At least 18 popular JavaScript code packages that are collectively downloaded more than two billion times each week were ...
An NPM supply chain attack has prompted Ledger Chief Technology Officer Charles Guillemet to urge crypto users to pause on-chain transactions.