News

A major supply chain attack on the NPM repository briefly threatened crypto users worldwide. Malicious code was pushed into ...
On September 8, 2025, a single phishing email triggered one of npm’s most damaging supply chain attacks, compromising 18 ...
An escalating npm supply chain attack has compromised dozens of foundational JavaScript packages to spread malware and drain ...
What could have been a historic supply chain attack seems to have been averted due to the rapid response of the open source ...
Binance reassures customers after a massive NPM supply chain attack injects malicious code into 18 popular JavaScript ...
Hackers are sharing malicious SVG files which spoof real-life websites in order to trick victims into downloading damaging ...
NPM supply chain attack compromised 18 popular JavaScript packages, swapping crypto wallet addresses, but quick detection ...
As developers lean on Copilot and GhostWriter, experts warn of insecure defaults, hallucinated dependencies, and attacks that ...
An NPM supply chain attack has prompted Ledger Chief Technology Officer Charles Guillemet to urge crypto users to pause ...
The malware was found in 18 npm packages that together are usually downloaded over 2 billion times per week. But the security ...
Npm packages are reusable blocks of JavaScript code published to the Node Package Manager registry that developers can ...
A new digital supply chain attack has targeted popular open-source npm packages with at least two billion downloads per week. On Sept. 8, Josh Junon, a package maintainer whose account was at the ...