Compromised Tensorlake npm Release Spreads Shai-Hulud Worm Through Developer Systems
A malicious Tensorlake npm release executed during installation, harvested developer and cloud secrets, and used worm-like techniques to threaten downstream projects. Teams that installed version 0.5.144 should treat...
Popular npm Package With Nearly 2 Million Weekly Downloads Hid Malware That Talks to Attackers Through Ethereum
Researchers at Checkmarx uncovered a supply-chain campaign hiding inside a widely used npm package that impersonates a legitimate data-structure library. Rather than infecting machines at install time, the...
ChainDrop Worm Spreads Through 400+ npm Packages, Raiding Developer and Cloud Credentials
A self-propagating worm dubbed ChainDrop has infected more than 400 npm packages by hijacking trusted publishing accounts, quietly harvesting npm, GitHub, cloud, and SSH credentials from developer machines...
Shai-Hulud Malware Expands to npm Ecosystem, Stealing Cloud and CI/CD Credentials From Developers
A credential-stealing malware campaign known as Shai-Hulud has expanded to target developers using the Leo/RStreams npm package ecosystem, harvesting GitHub tokens, cloud access keys, CI/CD secrets, and SSH...
Supply Chain Attack Compromises 140+ Mastra npm Packages, Targeting Developer Credentials and Crypto Wallets
A sophisticated supply chain attack has compromised over 141 packages in the Mastra-AI npm ecosystem, including @mastra/core which sees 918,000 weekly downloads. Detected on June 17, 2026, the...
Critical npm Supply Chain Attack: Malicious ‘dbmux’ Package Gives Hackers Full System Control
A malicious npm package named dbmux was discovered containing malware that gives attackers complete control over any developer system that installed it. Part of a coordinated wave of...
Critical Supply Chain Attack: 31 Red Hat Cloud Services npm Packages Backdoored to Steal Cloud and Dev Credentials
A sophisticated supply chain attack dubbed "Miasma: The Spreading Blight" has backdoored over 30 official @redhat-cloud-services npm packages, deploying credential-stealing malware that targets AWS, Azure, GCP secrets, GitHub...
Malicious npm Package forge-jsxy Pushes 22 Versions in 22 Days to Steal Crypto Wallets and Deploy Persistent Backdoor
The npm package forge-jsxy quietly stole cryptocurrency wallet keys, browser credentials, and developer data across Windows, macOS, and Linux — publishing 22 malicious versions in 22 days, and...