Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > npm supply chain
#npm supply chain

105 Minutes of Stolen Access Turned a Trusted npm Package Into a Multi-Stage Malware Loader

23 September 2026  |  dark6  |  Malware

Attackers hijacked a maintainer account for just 105 minutes to slip a hidden loader into a popular npm package, abusing legitimate publishing infrastructure so the poisoned release carried...

>> read more

Grafana GitHub Breach: TanStack npm Supply Chain Attack Leads to Source Code Theft and Ransom Demand

27 May 2026  |  dark6  |  Databreach

Grafana Labs has confirmed a ransomware-linked breach of its GitHub environment traced to the TanStack npm supply chain compromise. Attackers exfiltrated internal source code repositories and issued a...

>> read more

art-template npm Package Backdoored to Deliver iOS Browser Exploit Kit via Supply Chain Attack

24 May 2026  |  dark6  |  Malware

Attackers hijacked the widely-used art-template npm library by taking over its maintenance, then injected a sophisticated iOS browser exploit kit that silently targeted Safari users on vulnerable devices...

>> read more