Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > NPM
#NPM

Bitwarden CLI npm Package Compromised in Sophisticated GitHub Actions Supply Chain Attack

28 April 2026  |  dark6  |  Malware

Security researchers at Socket have confirmed that the official Bitwarden CLI npm package (version 2026.4.0) was tampered with via a compromised GitHub Actions workflow, injecting credential-stealing malware as...

>> read more

Malicious npm Package js-logger-pack Turns Hugging Face Into Malware CDN and Data Exfiltration Backend

24 April 2026  |  dark6  |  Malware

JFrog Security researchers have uncovered a malicious npm package, js-logger-pack, that uses Hugging Face as both a malware delivery network and an exfiltration backend for stolen data. The...

>> read more

Sophisticated npm malware campaign exploits Cross-Ecosystem typosquatting

3 May 2025  |  securebulletin.com  |  Malware

A coordinated malware operation targeting npm employs cross-ecosystem typosquatting to mimic popular libraries from Python, Java, C++, and .NET ecosystems. Attackers uploaded packages like beautifulsoup4 (masquerading as Python’s...

>> read more

Malicious NPM packages targeting PayPal users: a recap analysis

12 April 2025  |  securebulletin.com  |  Malware

FortiGuard Labs recently uncovered a series of malicious NPM packages designed to steal sensitive information from compromised systems. These packages, created between March 5 and March 14, were...

>> read more

North Korean hackers targeting NPM packages

3 September 2024  |  dark6  |  Spyware

In recent weeks, the cybersecurity landscape has witnessed a concerning uptick in malicious activities targeting developers through compromised NPM (Node Package Manager) packages. Researchers from Phylum have uncovered...

>> read more