A supply chain attack targeted the Jscrambler npm package, introducing an infostealer malware in version 8.14.0. The attack affected additional versions, including 8.16, 8.17, 8.18, and 8.20, each downloaded approximately 1,479 times.
The initial malicious payload was inserted through a compromised preinstall hook, deploying native binaries on installation across Windows, macOS, and Linux platforms.
After detecting the compromise, Jscrambler swiftly deprecated the affected versions and released a clean version, 8.22. Additional security measures were implemented to prevent further breaches.
Affected users were advised to update to the latest versions to avoid potential exposure of sensitive information such as cloud credentials and cryptocurrency wallets.
The attack highlighted vulnerabilities in the package publishing process, emphasizing the need for robust security protocols. The use of compromised publishing credentials allowed attackers to insert malicious code undetected initially.
Developers using open-source components must remain vigilant as supply chain attacks become more sophisticated and frequent.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The npm package "tensorlake" version 0.5.144 was compromised to deliver the Shai-Hulud credential-stealing worm. This malware harvests credentials, exfiltrates secrets, establishes persistence, and executes remote code, posing a supply chain risk to developers using the package.
Cybersecurity researchers identified eight malicious npm packages, downloaded 40,767 times, that distribute the Overlord RAT and information stealers. The campaign, active since August 2023, targets Windows systems to compromise Discord, browsers, Telegram, and cryptocurrency wallets. This highlights ongoing software supply chain risks within the npm ecosystem.
A long-running NPM supply chain campaign, dubbed MALFEX, has accumulated over 40,000 downloads since August 2023 by distributing malicious packages containing the Overlord RAT and infostealers. Checkmarx identified 12 packages, with eight being malicious, and three still installable as of October 1, impacting primarily Windows systems. This campaign highlights ongoing software supply chain vulnerabilities and the need for vigilance in package dependencies.
Cybersecurity researchers identified 101 malicious npm packages, downloaded 490,000 times, that exploit the 'Baileys' WhatsApp project to add developers' accounts to WhatsApp groups without consent. This campaign, dubbed PhantomSub, uses various methods to subscribe users to attacker-controlled channels, primarily for advertising mobile games and applications.
GitHub took 23 days to remove a malicious imitation of data wrangling software, which used the original product's name and logo and contained malware. The removal occurred shortly after the issue gained visibility on Hacker News, highlighting a delay in GitHub's response to reported malicious content.
Cybersecurity researchers have identified Go-based malware distributed through two Go Modules and two Terraform providers hosted on the HashiCorp registry, marking the first time this centralized repository has been used for malicious payload distribution. This campaign, linked to North Korean threat actors, uses social engineering to trick developers into installing dependencies that deliver the malware, which has also been found in new malicious npm packages.
A malicious npm package, "tw-pkgprobe-7731," was discovered on the npm registry, masquerading as a Twilio bug-bounty probe. The package was designed to exfiltrate environment variables and Twilio account credentials like ACCOUNT_SID and AUTH_TOKEN from developer environments. This incident highlights supply chain risks in software development, particularly for developers integrating third-party services.
A malicious NPM package, 'indexed-btree', mimicking a legitimate B-tree utility, has accumulated 2 million weekly downloads as part of an ongoing supply chain attack. The attacker bypassed NPM's protections by hiding malicious code in the package's JavaScript prototype, collecting system information, and using a blockchain contract for command-and-control.
A malicious npm package, "indexed-btree," was discovered to hide its loader within application code, bypassing recent npm security changes that prevent automatic execution of lifecycle scripts. This tactic shift by threat actors indicates an adaptation to new security measures, impacting software supply chain security.
A malicious npm package, 'indexed-btree', has been identified bypassing GitHub's npm security measures by hiding its payload in runtime code rather than installation scripts. This method allows the malware to execute without triggering security approvals, collecting system details and exfiltrating data. The campaign highlights a new technique for supply chain attacks that evades current static analysis and taint-analysis tools.
Cybersecurity researchers discovered 13 npm packages distributing a new JavaScript stealer, WeaselBiscuit, which harvests Chrome extension storage across multiple operating systems. This malware shares functional similarities with North Korean-linked BeaverTail and OtterCookie strains but is a smaller, stripped-down version.
A financially motivated threat actor, claiming to be a bug bounty hunter, used an LLM to create and distribute the PhantomRaven JavaScript information stealer via npm. This malware collected developer credentials and system information, indicating a new method for supply chain attacks and potential misuse of LLMs in malware development.
vlt 1.0, a JavaScript package manager and registry, has been released, offering a drop-in replacement for npm with features like phased installations, a queryable dependency graph, and hosted registries that block known malicious packages. This release provides developers with enhanced security and auditing capabilities for managing JavaScript dependencies.
Researchers demonstrated a trusting-trust attack against the NixOS Linux distribution by manipulating the GNU strip utility, proving this type of attack is not limited to compilers. The tampered strip propagated a payload through the build process, backdooring almost every binary in a complete graphical installer. This research expands the understanding of supply chain vulnerabilities beyond compilers to common build tools.
Threat actors are exploiting the legitimate Node.js JavaScript runtime to deploy malicious payloads in targeted attacks against government, technology, and hotel sectors since February 2026. This method allows attackers to bypass signature-based detection by running malicious code as interpreted scripts within a trusted, signed executable, establishing long-term access and delivering various malware.
Threat actors are abusing npm and its mirroring platforms like UNPKG to host malicious HTML pages that impersonate Cloudflare CAPTCHAs, redirecting visitors to attacker-controlled websites. This technique uses npm as free, validated storage for phishing content, bypassing some security measures by serving malicious pages from legitimate domains.
Researchers discovered a campaign using 24 npm packages to host fake Cloudflare CAPTCHA pages on unpkg mirrors, redirecting users to phishing sites. This method exploits trusted npm infrastructure to deliver malicious content, posing a risk to users who encounter these mirrored links.
Cybersecurity researchers discovered 14 trojanized npm packages that install the RedC2 4.0 Linux backdoor, a cross-platform command-and-control framework. These packages masquerade as functional calendar and streak utilities but secretly deploy a Linux implant for post-exploitation activities. This development highlights ongoing supply chain risks in software development, particularly within the npm ecosystem.
Cybersecurity researchers discovered 16 typosquatted RubyGems packages designed to steal browser credentials, cryptocurrency wallets, seed phrases, and Telegram data from users. The campaign exploited RubyGems' package name reuse and unvalidated author fields, allowing attackers to republish malicious versions of yanked gems.
Nearly 800 malicious packages were published to the npm registry, distributing cross-platform malware that targets Windows, Mac, and Linux systems. This campaign uses a novel method of infection, instructing developers to use `require()` to load the packages, which then execute a downloader for a RAT and infostealer payload.
Security researchers disclosed an npm supply-chain attack that affected over 400 packages, including projects like Keyv and Cacheable, by using stolen developer credentials to publish malicious versions. This incident highlights a vulnerability where malware can operate within trusted workflows and even carry valid provenance attestations, bypassing traditional security checks.
GitHub's Dependabot now provides malware advisories for eight major package ecosystems, including PyPI, Maven, and RubyGems, by integrating data from OpenSSF's malicious-packages repository. This expansion significantly broadens Dependabot's capability to detect and alert users about malicious packages beyond its previous npm-only scope, enhancing software supply chain security for a wider range of developers.
An attacker compromised a developer's GitHub account to inject a credential-stealing worm into keyv and related npm packages, affecting over 868 packages and two billion monthly installs. This attack is significant because the malicious releases carried valid provenance signatures, demonstrating that attackers can exploit trusted supply chain mechanisms.
Cybersecurity researchers identified NullReceiver, an evolution of the EtherHiding C2 technique, which embeds command-and-control server IP addresses within the recipient addresses of empty Ethereum transfers. This method, linked to North Korean threat actors, was found in trojanized npm packages and makes C2 detection more difficult by avoiding smart contracts or transaction payload fields.
A supply chain attack named ChainDrop infected 440 NPM packages with over 2,200 malicious versions, impacting packages with over 500 million weekly downloads. The malware steals credentials from developer workstations and CI/CD environments, then uses them to self-propagate by publishing poisoned package versions and infecting GitHub repositories.
Self-propagating malware named 'ChainDrop' has infected over 1,300 packages on the npm registry, affecting popular utilities and packages from major organizations. The attack started by compromising a GitHub account and spread through malicious files pushed directly to project branches, leading to valid but poisoned package releases. This incident highlights a significant supply-chain vulnerability in the JavaScript ecosystem, potentially exposing developer and cloud credentials to attackers.
A credential-stealing npm worm, initially found in keyv@6.0.0, spread to hundreds of packages across multiple organizations on August 4, 2026. This worm uses a preinstall script to harvest sensitive credentials and can plant Claude Code and VS Code hooks, posing a significant supply chain security risk for developers and CI environments.
Cybersecurity researchers discovered 18 malicious npm packages targeting users of Alibaba developer tools with a cross-platform remote access trojan (RAT). The attack uses unscoped packages that impersonate private Alibaba packages to deliver the RAT through a dependency tree, primarily affecting developers in Chinese-speaking environments.
Beta versions of two npm packages, @joyfill/layouts and @joyfill/components, have been compromised to install a remote access trojan (RAT) linked to the DEV#POPPER malware family. The malicious code executes upon package import in Node.js and uses a multi-blockchain resolver structure for command and control, indicating a sophisticated supply chain attack.
Researchers found a trojanized version of Newtonsoft.Json on NuGet, designed to rig game results on Digitain. This trojan is notable for functioning normally for most users while targeting a specific system, representing a significant security threat in the package management ecosystem.
Five malicious AsyncAPI packages were uploaded to npm, delivering a remote access trojan. Over 2.25 million weekly downloads of these packages raise significant supply-chain security concerns in the software development community.
Four npm packages in the @asyncapi namespace have been compromised to distribute a multi-stage botnet malware identified as Miasma. This incident is significant as it highlights vulnerabilities in widely used packages and poses risks for credential theft and other malicious activities.
Jscrambler's NPM package faced a supply chain attack, compromising multiple versions that included malicious code. The affected packages exposed sensitive data from developers' machines, raising concerns about the security of open-source dependencies.
A compromised version of the Jscrambler npm package was discovered to contain information-stealing malware that executed during the installation process and was downloaded nearly 1,500 times. Jscrambler quickly deprecated the affected releases and implemented additional security measures following the incident, which was attributed to compromised npm publishing credentials.
The jscrambler npm package version 8.14.0 was compromised to execute an infostealer upon installation. This malicious version, published on July 11, 2026, targets developers' sensitive information, including cloud credentials and cryptocurrency wallets, escalating security risks for users.