Search
Incidents (5)
Reports (10 of 91)
Six npm packages delivered an identical JavaScript loader, including three hijacked legitimate packages and three packages published with the malware already embedded. The loader used an Ethereum transaction as a dead drop, decoding command-and-control IP…
DPRK's PolinRider campaign automatically poisoned legitimate npm packages and Go modules after compromising developer machines, rather than deliberately selecting high-value packages for account takeover. OpenSourceMalware linked 20 analyzed packages thro…
Two malicious beta releases in the legitimate `@joyfill` npm scope executed an obfuscated loader when applications imported their production bundles. The loader resolved encrypted payloads through two successive Tron-to-BSC transaction chains, selected C2…
Two Joyfill beta packages contained an import-time JavaScript implant that used Tron, Aptos, and BNB Smart Chain transactions to resolve mutable payloads. The recovered chain delivered a DEV#POPPER Node.js RAT capable of remote command execution, file tra…
Malicious prerelease builds of `@joyfill/components` and `@joyfill/layouts` executed an obfuscated Node.js loader when imported, bypassing protections focused on npm installation scripts. The implant used blockchain transactions to resolve later stages, d…
Checkmarx identified seven malicious npm packages that impersonated Vite-related scopes and delivered an obfuscated remote-access trojan through Tron, Aptos, and Binance Smart Chain infrastructure. Shared wallets, XOR keys, loader structure, and payloads …
`nodemon-sudo` v3.1.16 is a malicious npm lookalike that copies legitimate nodemon while adding an unused dependency on `tslint-conf`, a repackaged pino logger containing the backdoor. The payload avoids install hooks and import-time execution; it runs on…
JFrog identified a Lazarus-linked npm supply-chain campaign that hid malicious code in Rollup-themed lookalike packages and SVG utility second stages. The packages fetched a JSONKeeper payload, decrypted a remote stage from 216.126.236.244, and launched N…
Sapphire Sleet compromised the `ehindero` npm maintainer account and injected the malicious `[email protected]` dependency into 144 Mastra AI npm packages during an 88-minute window on June 17, 2026. The postinstall hook executed an obfuscated JavaScrip…
The malicious npm packages `chalk-ultra` and `vitest-cli` execute a hidden downloader that steals developer credentials, source code, browser data, and cryptocurrency-wallet information. The payload can replace Chrome's MetaMask extension with a persisten…