Search

← All results for "npm"

Reports (91)

2026-07-28 • Socket

Two Joyfill beta packages contained an import-time JavaScript implant that used Tron, Aptos, and BNB Smart Chain transactions to resolve mutable payloads. The recovered chain delivered a DEV#POPPER Node.js RAT capable of remote command execution, file tra…

#SupplyChain #NPM #DevPopper #OmniStealer #PolinRider #T1027.013 #T1071.001 #T1195.002 #T1115 #T1059.006 #T1059.007 #T1059.004 #T1027 #T1105 #Joyfill
2026-06-17 • Microsoft

Sapphire Sleet compromised the Mastra npm ecosystem by taking over the `ehindero` maintainer account and injecting the malicious `easy-day-js` typosquat into more than 140 `mastra` and `@mastra` packages. The weaponized package ran a postinstall dropper t…

#SupplyChain #NPM #SapphireSleet #T1071.001 #T1195.002 #T1059.007 #T1027 #T1547.001 #T1059.001 #T1105 #T1055 #T1562.001 #T1543.003 #Mastra
2026-04-03 • Cisco Talos

Cisco Talos found that attackers published malicious Axios npm versions 1.14.1 and 0.30.4 on March 31, 2026, leaving the widely used JavaScript HTTP client exposed for about three hours. The modified packages introduced a fake dependency, plain-crypto-js,…

#NPM #Axios
2026-03-31 • Sophos

Sophos CTU reported that Axios versions 1.14.1 and 0.30.4 were compromised after an apparent npm maintainer account takeover and used to deploy a cross-platform RAT. The malicious dependency executed during installation, retrieved platform-specific second…

#NPM #Axios
2026-03-31 • Trend Micro

Trend Micro reported that attackers hijacked the Axios npm maintainer account and manually published malicious Axios versions 1.14.1 and 0.30.4 using stolen credentials rather than the project’s normal OIDC Trusted Publisher workflow. The poisoned release…

#NPM #Axios #T1082 #T1070.004 #T1071.001 #T1195.002 #T1059.006 #T1036 #T1027 #T1059.005 #T1059.001 #T1620
2025-11-26 • Socket

Socket tracks North Korea’s Contagious Interview operation expanding its npm supply-chain activity with at least 197 additional malicious packages and more than 31,000 downloads, targeting blockchain and Web3 developers through fake interviews and test as…

#NPM #ContagiousInterview #OtterCookie #T1082 #T1119 #T1005 #T1587.001 #T1041 #T1113 #T1608.001 #T1195.002 #T1115 #T1083 #T1497 #T1056.001 #T1059.007 #T1036 #T1204.002 #T1555.003 #T1583.006 #T1547.001 #T1539 #T1583.001 #T1656 #T1105 #T1204.005 #T1571 #T1657 #T1587 #T1585 #T1555.001 #T1546.016 #T1217
2025-11-20 • Jfrog

JFrog found a two-part npm cryptocurrency stealer that paired a benign-looking Ethereum address validation package with a malicious transitive dependency. The visible package exported ordinary address-checking functions, but dynamically imported aes-core-…

#NPM
2025-10-10 • Socket

Socket tracks North Korea’s Contagious Interview operation as a weekly, wave-based abuse of npm, identifying more than 338 malicious packages with over 50,000 downloads and 25 still live at publication time. The campaign uses fake recruiter personas, Link…

#NPM #ContagiousInterview #T1027.013 #T1082 #T1119 #T1005 #T1041 #T1608.001 #T1195.002 #T1083 #T1059.007 #T1204.002 #T1555.003 #T1105 #T1657 #T1555.001 #T1546.016 #T1217
2025-07-15 • Socket

Socket reports that North Korean Contagious Interview operators expanded their software supply-chain activity with 67 malicious npm packages, including 28 tied to the newly identified XORIndex loader and 39 new HexEval packages. XORIndex collects host met…

#NPM #ContagiousInterview #XORIndex #T1027.013 #T1082 #T1119 #T1005 #T1041 #T1608.001 #T1195.002 #T1083 #T1059.007 #T1204.002 #T1555.003 #T1105 #T1657 #T1555.001 #T1546.016 #T1217
2025-06-25 • Socket

Socket attributes a continuing North Korean Contagious Interview supply-chain campaign to 35 malicious npm packages published across 24 accounts, including six packages that remained live and had more than 4,000 downloads. The packages target developers a…

#NPM #ContagiousInterview #BeaverTail #HexEval #T1027.013 #T1082 #T1119 #T1005 #T1041 #T1608.001 #T1195.002 #T1083 #T1056.001 #T1059.007 #T1204.002 #T1555.003 #T1105 #T1657 #T1555.001 #T1546.016 #T1217
2025-04-09 • Veracode

Veracode describes a renewed North Korean npm malware campaign that targets developers with malicious packages disguised as logging, validation, React, or utility libraries. The packages appear designed for social-engineering workflows in which a target r…

#NPM #Lazarus
2025-03-10 • Socket

North Korea’s Lazarus Group continues to infiltrate the npm ecosystem, deploying six new malicious packages designed to compromise developer environments, steal credentials, extract cryptocurrency data, and deploy a backdoor. The secondary payload (SHA256…

#NPM #Lazarus #T1027.013 #T1082 #T1119 #T1005 #T1041 #T1608.001 #T1195.002 #T1083 #T1059.007 #T1204.002 #T1555.003 #T1105 #T1657 #T1555.001 #T1546.016 #T1217
2024-04-24 • Phylum

Phylum linked new npm publications on 23 April 2024 to a previously reported North Korea-attributed campaign against open-source package ecosystems. The packages react-dom-production-script and hardhat-daemon used a preinstall hook to run deference.js as …

#macOS #NPM
2024-01-05 • Phylum

Phylum reports that a crypto-themed npm package campaign first described in November remained active, with nearly two dozen additional packages identified through December 2023. The packages download a remote binary during installation, decrypt and execut…

#SupplyChain #NPM
2023-07-22 • Phylum

Phylum linked a June 2023 npm supply-chain campaign to GitHub’s high-confidence attribution to Jade Sleet, also known as TraderTraitor, a group operating in support of North Korean objectives. The campaign targeted personal accounts of technology-firm emp…

#NPM
2023-06-23 • Phylum

Phylum observed a coordinated npm supply-chain campaign in which malicious packages were published in pairs that had to run sequentially on the same host. The first package used a preinstall hook to install sync-request, contact an attacker server, and wr…

#NPM