Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect ...
To install and use Gemini CLI, meet the prerequisite requirements, install Node.js, install Gemini using npm, authenticate ...
TL;DR Sonatype Research Labs identified six npm packages delivering the same malicious payload: three hijacked legitimate ...
The two critical vulnerabilities reported by Vercel in the JavaScript framework Next.js allow attackers to execute code.
Learn how to add Google's Preferred Sources button to a website, compare the embed and deeplink, and build a WordPress widget ...
keyv npm supply chain attack on August 4, 2026 let the Shai-Hulud worm compromise 400-plus packages and more than two billion monthly downloads. The Wave Six payload hid inside AI agent config files ...
ChainDrop hijacked 444 npm packages and 2B monthly downloads via a Claude Code hook. AI agents have collapsed the gap between ...
Upwind was the first to publicly report that [email protected], a widely used npm package with 154 million weekly downloads, contained a malicious preinstall script that harvested AWS credentials, ...
Trojanized npm packages launch RedC2 4.0 on Linux at import time, giving operators shell access, credential theft, and ...
攻击者不再只是发布一个明显的恶意包,而是开始模仿企业内部依赖、拆分攻击代码,并针对具体开发环境设计完整攻击链。 最近 npm 生态接连发生了两件值得关注的事情。 一边,是针对阿里巴巴开发环境的 npm 木马攻击;另一边,是 npm 开始强化软件包发布审核机制。 npm 供应链安全正在变得越来越重要。 阿里遭遇定向 npm 木马攻击 安全公司 Socket 最近披露了一起针对阿里巴巴开发环境的 np ...
Modern AI agents have become a new supply chain layer and how cybercriminals are exploiting the gap between the chain of ...
Cybersecurity researchers have uncovered 24 malicious npm packages that abuse package mirror services to host obfuscated ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results