All posts tagged "npm"
-
Security
/ 2 weeks agoAnthropic Confirms Internal Claude Code Leaked in Packaging Error
On Tuesday, Anthropic confirmed that internal source code for its Claude Code artificial intelligence assistant was inadvertently released due to a...
-
Security
/ 2 weeks agoGoogle Links Axios npm Attack to North Korean Hackers
Google has formally attributed a recent software supply chain attack to a North Korean state-sponsored hacking group. The attack targeted the...
-
Security
/ 2 weeks agoAxios npm Package Compromised in Supply Chain Attack
Two versions of the widely used Axios HTTP client library were found to contain malicious code this week, following a compromise...
-
Security
/ 3 weeks agoMalicious npm Packages Steal Crypto Wallets in ‘Ghost’ Campaign
cybersecurity researchers have identified a new set of malicious software packages within the widely used npm registry, designed to steal cryptocurrency...
-
Security
/ 4 weeks agoSupply Chain Attack Spreads Worm Through npm Packages
A significant software supply chain attack has compromised dozens of popular npm packages, deploying a self-propagating worm. Security researchers report that...
-
Security
/ 1 month agoMalicious npm Package Poses as AI Tool to Deploy macOS RAT
cybersecurity researchers have identified a malicious package on the npm software registry that impersonates an installer for an artificial intelligence tool...
-
Security
/ 1 month agoNorth Korean Hackers Deploy Malicious npm Packages in Global Campaign
cybersecurity researchers have identified a new phase of a persistent cyber espionage campaign, attributed to North Korean state-sponsored actors, involving the...
-
Security
/ 2 months agoCline CLI Supply Chain Attack Installs OpenClaw Malware
An open-source coding assistant tool was compromised in a software supply chain attack, leading to the unauthorized installation of a popular...
-
Security
/ 2 months agonpm Completes Major Security Overhaul Following Supply Chain Incident
In December 2025, the Node.js package manager, npm, completed a significant authentication system overhaul. This update was a direct response to...
-
Security
/ 2 months agoLazarus Group Targets npm, PyPI with Malicious Software Packages
cybersecurity researchers have identified a new series of malicious software packages within the npm and Python Package Index (PyPI) ecosystems. These...

