cyber-crime Amazon links four poisoned npm packages to one North Korean crew Researchers say Sapphire Sleet socially engineered maintainers before publishing malicious updates through trusted accounts
security Miasma campaign poisons 20-plus npm packages, hunts for developer secrets Microsoft says latest attack targets Leo Platform and RStreams packages, harvesting creds and going after more maintainers
Security Sniff out stale AI override advice with this open source CLI Package dependencies can create vulnerabilities that are fiendishly hard to find and stamp out
AI AND ML Python dev saved from disaster by intuition... and AI I'm sorry, Dave. I can't install that repo that will totally hose your system
Security Arch Linux locks down AUR signups amid wave of malicious commits Community repo freezes new accounts after attackers swamp it with poisoned package updates
AI AND ML AI is code – and can't be prompted into being smarter From Java tests to Shai-Hulud, bots keep proving they'll swallow anything you feed them
ai and ml NanoClaw now armed with JFrog for safer packages AI agents can't be trusted, so don't give them dangerous powers
DevOps GitHub pulls pin on npm's auto-run scripts Shai-Hulud worm exploited exactly this. Better late than never, says everyone except the malware authors
Security Shai-Hulud malware worms Red Hat npm package versions downloaded 80K times a week TeamPCP? Or copycat malware dev?
Security Lone attacker published 14 malicious npm packages mimicking popular OpenSearch, Elasticsearch libraries And then Microsoft busted them all
cyber-crime Malware dev tries to steal Claude users' secrets, writes npm slop, leaks own GitHub private token Script kiddies these days
AI + ML Npm registry sets stage for more secure package publishing All the world's a stage, and all the packages are merely players
Cyber-crime Shai-Hulud keeps burrowing: 314 npm packages infected after another account compromise Popular JavaScript modules including size-sensor and echarts-for-react hit as hijacked account closed GitHub warnings
Cyber-Crime Shai-Hulud copycat worm infects yet another npm package Plus three other stealers in three other packages, all from the same scumbag
Security OpenAI caught in TanStack npm supply chain chaos after employee devices compromised Attackers stole a limited amount of internal credential material after malware hidden in poisoned packages reached two staff machines
Security Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub Where it’s been well and truly forked, seemingly without Microsoft’s code locker noticing
Cyber-crime Cache-poisoning caper turns TanStack npm packages toxic Six-minute supply chain blitz pushed 84 malicious versions with credential theft and disk-wiping code
CSO Supply chain blast: Top npm package backdoored to drop dirty RAT on dev machines Hijacked maintainer account let attackers slip cross-platform trojan into 100M-downloads-a-week Axios
Software npmx package browser released as alpha to fix pain of using npmjs Project initiated by Nuxt lead Daniel Roe attracts wide support thanks to multiple issues with the official interface
Cyber-crime Poisoned WhatsApp API package steals messages and accounts And it's especially dangerous because the code works
Devops PostHog admits Shai-Hulud 2.0 was its biggest ever security bungle Automation flaw in CI/CD workflow let a bad pull request unleash worm into npm
Cyber-crime Shai-Hulud worm returns, belches secrets to 25K GitHub repos Trojanized npm packages spread new variant that executes in pre-install phase, hitting thousands within days
Security Logitech leaks data after zero-day attack PLUS: CISA still sitting on telecoms security report; DoorDash phished again; Lumma stealer returns; and more
Security Invisible npm malware pulls a disappearing act – then nicks your tokens PhantomRaven slipped over a hundred credential-stealing packages into npm
Security GitHub moves to tighten npm security amid phishing, malware plague Hundreds of compromised packages pulled as registry shifts to 2FA and trusted publishing
Cybersecurity Month Self-propagating worm fuels latest npm supply chain compromise Intrusions bear the same hallmarks as recent Nx mess
Cyber-crime More packages poisoned in npm attack, but would-be crypto thieves left pocket change Miscreants cost victims time rather than money
Security Dev snared in crypto phishing net, 18 npm packages compromised Popular npm packages debug, chalk, and others hijacked in massive supply chain attack
Devops Nx NPM packages poisoned in AI-assisted supply chain attack Stolen dev credentials posted to GitHub as attackers abuse CLI tools for recon
Security Someone's poking the bear with infostealers targeting Russian crypto developers If you wanted to hurt Putin’s ransomware racketeers, these info-stealing npm packages are one way to do it
AI + ML Rampant emoji use suggests crypto-stealing NPM package was written by AI Kodane code was either machine-generated or done by a teenager
Cyber-crime Freelance dev shop Toptal caught serving malware after GitHub account break-in Malicious code lurking in over 5,000 downloads, says Socket researcher
Security Not pretty, not Windows-only: npm phishing attack laces popular packages with malware The "is" package was infected with cross-platform malware after a scam targeting maintainers
Cyber-crime Ripple NPM supply chain attack hunts for private keys A mystery thief and a critical CVE involved in crypto cash grab
Research North Korea targets crypto developers via NPM supply chain attack Yet another cash grab from Kim's cronies and an intel update from Microsoft
Security Snyk appears to deploy 'malicious' packages targeting Cursor for unknown reason Packages removed, vendor said to have apologized to AI code editor as onlookers say it could have been a test
Cyber-crime Solana blockchain's popular web3.js npm package backdoored to steal keys, funds Damage likely limited to those running bots with private PKI access
Cyber-crime Hundreds of thousands of dollars in crypto stolen after Ledger code poisoned Former worker phished then NPM repo hijacked
Research Warning: JavaScript registry npm vulnerable to 'manifest confusion' abuse Failure to match metadata with packaged files is perfect for supply chain attacks
Storage Hijacked S3 buckets used in attacks on npm packages Cybercrooks use abandoned AWS storage tool to deliver malware
Devops So you want to integrate OpenAI's bot. Here's how that worked for software security scanner Socket Hint: Hundreds of malicious npm and PyPI packages spotted
Security Cry Havoc and let slip dogs of war ... there's an upgraded malware server in town ThreatLabz finds free alternative to Cobalt Strike and other tools used in the wild
Security Malicious PyPI package found posing as a SentinelOne SDK Security firm tagged with malware misrepresentation
Security Boffins rate npm and PyPI package security and it's not good Guess what? Open source security still has gaps
Research Miscreants aim to cause Discord discord with malicious npm packages LofyLife campaign comes amid GitHub security lockdown
Research Someone may be prepping an NPM crypto-mining spree 1,300 packages from 1,000 automated user accounts set the stage for something big
Security GitHub saved plaintext passwords of npm users in log files, post mortem reveals Unrelated to the OAuth token attack, but still troubling as org reveals details of around 100,000 users were grabbed by the baddies
CSO How to find NPM dependencies vulnerable to account hijacking Security engineer outlines self-help strategy for keeping software supply chain safe
Devops Mystery of industry-targeting backdoored NPM JavaScript packages solved Yup, 'the intern' did it
CSO Email domain for NPM lib with 6m downloads a week grabbed by expert to make a point Campaign to coax GitHub-owned outfit to improve security starts showing results
Security This JavaScript scanner hunts down malware in libraries Stick a fork in this Socket and zap malicious NPM packages
Security Worried about occasional npm malware scares? It's more common than you may think WhiteSource says it spotted 1,300 malicious JavaScript packages in 2021 alone
Security GitHub fixes authorisation vulnerability in the NPM JavaScript package registry Flaw allowed 'an attacker to publish new versions of any npm package'
Security NPM packages disguised as Roblox API code caught carrying ransomware Subverted libraries likely intended as a prank but should be taken seriously, say security researchers
Devops NPM is Now Providing Malware – or was until recently Password-stealing package outed by security firm evokes sense of déjà vu
Security Sitting comfortably? Then it's probably time to patch, as critical flaw uncovered in npm's netmask package Are you local? Catastrophically local?
Devops Malicious backdoored NPM package masqueraded as Twilio library for three days until it was turfed out Dodgy JavaScript code downloaded hundreds of times
Software Now GitHub has gulped down NPM Inc, what's next for the JS package registry? Well, some stability will be nice CTO Ahmad Nassri announces intention to bow out
Devops Are we having fund yet, npm? CTO calls for patience after devs complain promised donations platform has stalled Funding free software is 'still a very unsolved problem' says co-founder
Software No big deal, Rogers, your internal source code and keys are only on the open web. Don't hurry to take it down 'Closed source' blueprints available for all to gawp at – and potentially exploit
Security NPM swats path traversal bug that lets evil packages modify, steal files. That's bad for JavaScript crypto-wallets Trio of vulnerabilities made registry full of uncertain code even more of a risk
Software NPM today stands for Now Pay Me: JavaScript packaging biz debuts conduit for funding open-source coders Like a particular module? You're one command away from being able to donate some dosh for it
Devops Hey, NPM. How do you like your Bogensberger? He's, well, done: CEO Bryan ejects from biz JavaScript packager seeks new boss amid internal friction, firings, unionization attempts
Software After banning adverts in command-line terminals, NPM floats idea of Patreon-style donations to open-source devs Cash-burning biz sees itself following in the footsteps of GitHub Sponsors
Software NPM Inc settles union-busting complaints on third try – after CEO trolled for ordering internal mole hunt Stuffed mole toys arrive at JavaScript biz after chief exec demands to know who was talking to El Reg
Software settlement.js not found: JavaScript package biz NPM scraps talks, fights union-busting claims CEO speaks to The Reg as we dig into labor complaints, future of npm CLI
Software NPM is Not Particularly Magnanimous? Staff fired after trying to unionize – complaints Plus: Employee diversity, harassment brouhahas within Microsoft, Google
On-Prem NPM apologizes for ham-fisted handling of recent staff layoffs Sorry song fails to quell online discontent, rumors swirl of competition ahead
Devops NPM not tied in knots over Yarn rival project Parallel projects just happen when the future is obvious
Security One-in-two JavaScript project audits by NPM tools sniff out at least one vulnerability... ...and those devs are then applying patches, we hope
Security Now Pushing Malware: NPM package dev logins slurped by hacked tool popular with coders Tokens killed after eslint-scope utility compromised
Software Unlucky Linux boxes trampled by NPM code update, patch zapped Devs stumble into pre-release beta by using command they didn't understand
Software Wondering where your JavaScript libs went? Spam-detection snafu exiled npm packages Postmortem sheds light on brief dependency hell
Devops npm adds two-factor auth, security tokens in wake of JS typo attack Let's make sure that code you're pulling in is legit code, not some scumbag's library
Security This typosquatting attack on npm went undetected for 2 weeks Lookalike npm packages grabbed stored credentials
Software 'No regrets' says chap who felled JavaScript's Jenga tower – as devs ask: Have we forgotten how to code? NPM republishes unpublishing rules
Software How one developer just broke Node, Babel and thousands of projects in 11 lines of JavaScript Code pulled from NPM – which everyone was using