Latest news
Critical Supply Chain Attack: 31 Red Hat Cloud Services npm Packages Backdoored to Steal Cloud and Dev Credentials
2 June 2026 dark6
Malicious npm Package forge-jsxy Pushes 22 Versions in 22 Days to Steal Crypto Wallets and Deploy Persistent Backdoor
29 May 2026 dark6
Four Malicious npm Packages Steal SSH Keys, Cloud Credentials, and Crypto Wallets in Coordinated Supply Chain Attack
19 May 2026 dark6
84 TanStack npm Packages Poisoned in Sophisticated Supply-Chain Attack Stealing Cloud and CI Credentials
15 May 2026 dark6
CVE-2026-43898: Critical SandboxJS Escape (CVSS 10.0) Enables Full Host Takeover via npm
15 May 2026 dark6
Bitwarden CLI npm Package Compromised in Sophisticated GitHub Actions Supply Chain Attack
28 April 2026 dark6
Malicious npm Package js-logger-pack Turns Hugging Face Into Malware CDN and Data Exfiltration Backend
24 April 2026 dark6
Sophisticated npm malware campaign exploits Cross-Ecosystem typosquatting
3 May 2025 securebulletin.com
Malicious NPM packages targeting PayPal users: a recap analysis
12 April 2025 securebulletin.com
North Korean hackers targeting NPM packages
3 September 2024 dark6