News

In a supply chain attack, attackers have injected malware into NPM packages with over 2.6 billion weekly downloads after ...
What could have been a historic supply chain attack seems to have been averted due to the rapid response of the open source ...
An escalating npm supply chain attack has compromised dozens of foundational JavaScript packages to spread malware and drain ...
On September 8, 2025, a single phishing email triggered one of npm’s most damaging supply chain attacks, compromising 18 ...
A JavaScript supply chain attack has delivered a crypto-clipper via 18 npm packages; Ledger’s CTO has warned ...
A new digital supply chain attack has targeted popular open-source npm packages with at least two billion downloads per week. On Sept. 8, Josh Junon, a package maintainer whose account was at the ...
Hackers hijacked NPM libraries in a massive supply chain attack, injecting malware that swaps crypto wallet addresses to steal funds.