← All stories
● Covered by 8 sources · 35 reportsMedium impact26 negative3 neutral

Jscrambler npm Package Supply Chain Attack Deploys Infostealer

🔄 Updated 1d ago — new reporting from The Hacker News
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Jscrambler npm package versions 8.14.0 and others were compromised.
  • The attack involved a preinstall hook deploying malware.
  • The malicious versions were downloaded about 1,479 times.
  • Jscrambler quickly deprecated the affected versions.
  • The incident stemmed from compromised npm publishing credentials.
  • The attack involved 16 typosquatted RubyGems packages.
  • The malicious packages steal browser credentials, crypto wallets, seed phrases, and Telegram data.
  • OpenSourceMalware discovered the activity on August 15, 2026.
  • OpenSourceMalware tracks the threat under the moniker StubMaker.
  • The packages were published by users "mod8rz41mje" (Riley Miller) and "rbq95bwt6q" (Alex Davis).
  • 14 trojanized npm packages install the RedC2 4.0 Linux backdoor.
  • The packages masquerade as calendar and streak utilities.
  • The malicious module loads a bundled binary, marks it executable, and launches it.
  • No install hook function call is needed to execute the payload.
  • TrendAI published a report on the discovery.
  • 24 npm packages host fake Cloudflare CAPTCHA pages on unpkg mirrors.
  • The malicious npm packages redirect users to phishing sites.
  • OX Security researchers Moshe Siman Tov Bustan and Vitalii Chepurko discovered the campaign.
  • The npm packages are used as free phishing infrastructure.
  • The malware is a single HTML page inside the npm package.
  • The threat actor uses the npm registry and mirrors for validated storage of malware.
  • The campaign targets mirrors like unpkg.
  • Inf0stache first spotted the technique in July.
  • The 'china_airlines' npm package used a fake Cloudflare verification page.
  • Threat actors use Node.js runtime to deploy malicious payloads.
  • Attacks target government, technology, and hotel sectors since February 2026.
  • The technique bypasses signature-based detection by running malicious code as interpreted scripts.
  • A registry Run key entry relaunches the payload at every login.
  • One intrusion between March 23 and July 25, 2026, targeted an Asian technology company.
  • Attackers downloaded the official Node.js installer from nodejs[.]org.
  • The malicious implant establishes long-term access and retrieves commands using EtherHiding.
  • The Symantec Threat Hunter Team published a report on the discovery.
  • vlt 1.0, a JavaScript package manager, has been released.
  • vlt was built by the original creators of npm.
  • vlt 1.0 offers phased installations.
  • vlt 1.0 includes a queryable dependency graph.
  • vlt 1.0 features hosted registries that block known malicious packages.
  • Darcy Clarke announced the vlt release on X.
  • vlt install downloads and extracts packages without executing anything.
  • vlt build runs approved scripts and blocks known malware.
  • vlt query is a dependency selector syntax.
  • Researchers demonstrated a trusting-trust attack against the NixOS Linux distribution.
  • The attack manipulated the GNU strip utility.
  • The tampered strip propagated a payload through the build process.
  • The attack backdoored almost every binary in a complete graphical installer.
  • The research expands understanding of supply chain vulnerabilities beyond compilers to common build tools.
  • A financially motivated threat actor developed and distributed PhantomRaven via npm.
  • PhantomRaven is a JavaScript-based information stealer.
  • The developer likely used an LLM to write the PhantomRaven malware.
  • CrowdStrike's Counter Adversary Operations published an analysis of PhantomRaven.
  • PhantomRaven was first flagged by Koi Security and DCODX in late October 2025.
  • PhantomRaven was distributed via a slopsquatting and typosquatted campaign.
  • Over 100 malicious packages were uploaded to npm in the PhantomRaven campaign.
  • PhantomRaven steals authentication tokens, CI/CD secrets, and GitHub credentials.
  • The attack used packages to retrieve a remote dynamic dependency from an external server.
  • The malware scans the developer environment for email addresses.
  • The malware gathers information about the CI/CD environment.
  • The malware collects a system fingerprint, including the public IP address.
  • 13 npm packages distribute the WeaselBiscuit JavaScript stealer.
  • WeaselBiscuit harvests Chrome extension storage.
  • WeaselBiscuit shares functional similarities with BeaverTail and OtterCookie malware.
  • WeaselBiscuit is a smaller, stripped-down version of BeaverTail and OtterCookie.
  • Paul McCarty (6mile) and Jenn Gile of OpenSourceMalware named the malware WeaselBiscuit.
  • The 'indexed-btree' npm package hides its payload in runtime code.
  • The 'indexed-btree' package impersonates the 'sorted-btree' library.
  • The 'indexed-btree' package has 2 million weekly downloads.
  • Attackers use a wallet holding 109 ETH.
  • GitHub announced npm security measures in June 2026.
  • The measures block dependency lifecycle scripts unless explicitly approved.
  • The measures prevent npm from automatically retrieving dependencies from Git repositories or remote URLs without permission.
  • The 'indexed-btree' package was uploaded on June 18, 2026.
  • The 'indexed-btree' package was uploaded by user "charlessadler25".
  • The 'indexed-btree' package generated €230,933.57 in cryptocurrency.
  • The 'indexed-btree' package and GitHub repository are no longer available.
  • The malicious trigger was hidden in the package's JavaScript prototype code.
  • The threat actor created a legitimate-looking GitHub repository for 'indexed-btree'.
  • A malicious npm package, "tw-pkgprobe-7731," was discovered.
  • The package masquerades as a Twilio bug-bounty probe.
  • The package exfiltrates environment variables and Twilio account credentials.
  • The package was uploaded in mid-August 2026 by "twdepprobe7731."
  • 11 versions of the package were published in 45 minutes.
  • The npm user account "twdepprobe7731" no longer exists.
  • ReversingLabs researcher Lucija Valentić published a report on the package.
  • Go-based malware was distributed via two Go Modules and two Terraform providers.
  • This is the first time HashiCorp registry was used for malicious payload distribution.
  • The malicious Terraform providers are gocommunity-io/dockerd and kreuzwenker/docker.
  • The malicious Go modules are gocommunity.io/orderedbtree and gogets.dev/btreex.
  • The gocommunity-io/dockerd provider had 222 downloads.
  • The kreuzwenker/docker provider had 1,449 downloads.
  • The malware overlaps with Graphalgo, attributed to North Korean threat actors.
  • Attackers use social engineering on LinkedIn, Facebook, or job forums.
  • Attackers pose as non-existent Web3 companies.
  • Attackers ask developers to complete a coding task with a benign GitHub repository.
  • The GitHub repository introduces malicious behavior via an npm or PyPI dependency.
  • A malicious imitation of data wrangling software was reported to GitHub on August 31.
  • The malicious software used the original product's name and logo without permission.
  • The malicious .dmg file contained malware warnings on virustotal.com.
  • The malicious .dmg file's background image encouraged users to ignore malware warnings.
  • GitHub took 23 days to remove the malicious imitation software.
  • 101 malicious npm packages were identified.
  • The packages were downloaded 490,000 times.
  • The packages exploit the 'Baileys' WhatsApp project.
  • The packages add developers' accounts to WhatsApp groups without consent.
  • The campaign is dubbed PhantomSub.
  • The campaign primarily advertises mobile games and applications.
  • Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko published a technical write-up.
  • 116,000 downloads occurred in the last 30 days.
  • SafeDep first identified the activity in August 2026.
  • A campaign dubbed MALFEX distributed Overlord RAT and infostealers.
  • The MALFEX campaign has accumulated over 40,000 downloads.
  • The MALFEX campaign has been ongoing since August 2023.
  • Checkmarx identified 12 packages in the MALFEX campaign, with eight being malicious.
  • Three MALFEX packages (function-flag, function-color, cdn-img-fetch) were still installable as of October 1.
  • The 'function-flag' package has been malicious since July 2025 and has over 37,000 downloads.
  • OSV advisories exist for six MALFEX packages: tlxbnhd, tldriver, mxdriver, img-to-native, native-runner, and cdn-img-fetch.
  • Checkmarx identified three independent delivery paths in the MALFEX campaign.
  • The MALFEX campaign targets Windows systems.
  • The MALFEX campaign compromises Discord, browsers, Telegram, and cryptocurrency wallets.
  • The MALFEX campaign uses a loader for Overlord, an open-source RAT written in Go.
  • Overlord RAT uses Solana transactions to extract the command-and-control (C2) address.
  • The MALFEX campaign uses movinlike, a Node.js stealer.
  • The 'function-flag' package accounts for 37,419 downloads.
  • The npm package "tensorlake" version 0.5.144 was compromised.
  • The malware is called Shai-Hulud credential-stealing worm.
  • The malicious version 0.5.144 is no longer available for download.
  • The malware uses the Bun runtime.
  • The stealer malware harvests credentials across local files, CI environments, Kubernetes, and Vault sources.
  • The malware drops the HackBrowserData binary.

Compromise of Jscrambler Npm Package

A supply chain attack targeted the Jscrambler npm package, introducing an infostealer malware in version 8.14.0. The attack affected additional versions, including 8.16, 8.17, 8.18, and 8.20, each downloaded approximately 1,479 times.

The initial malicious payload was inserted through a compromised preinstall hook, deploying native binaries on installation across Windows, macOS, and Linux platforms.

Immediate Response and Mitigation

After detecting the compromise, Jscrambler swiftly deprecated the affected versions and released a clean version, 8.22. Additional security measures were implemented to prevent further breaches.

Affected users were advised to update to the latest versions to avoid potential exposure of sensitive information such as cloud credentials and cryptocurrency wallets.

Backdoor Damage and Security Concerns

The attack highlighted vulnerabilities in the package publishing process, emphasizing the need for robust security protocols. The use of compromised publishing credentials allowed attackers to insert malicious code undetected initially.

Developers using open-source components must remain vigilant as supply chain attacks become more sophisticated and frequent.

Updates

🕒 2026-10-08 · new reporting from The Hacker News
  • The npm package "tensorlake" version 0.5.144 was compromised.
  • The malware is called Shai-Hulud credential-stealing worm.
  • The malicious version 0.5.144 is no longer available for download.
  • The malware uses the Bun runtime.
  • The stealer malware harvests credentials across local files, CI environments, Kubernetes, and Vault sources.
  • The malware drops the HackBrowserData binary.
🕒 2026-10-07 · new reporting from The Hacker News
  • The MALFEX campaign targets Windows systems.
  • The MALFEX campaign compromises Discord, browsers, Telegram, and cryptocurrency wallets.
  • The MALFEX campaign uses a loader for Overlord, an open-source RAT written in Go.
  • Overlord RAT uses Solana transactions to extract the command-and-control (C2) address.
  • The MALFEX campaign uses movinlike, a Node.js stealer.
  • The 'function-flag' package accounts for 37,419 downloads.
🕒 2026-10-06 · new reporting from SecurityWeek
  • A campaign dubbed MALFEX distributed Overlord RAT and infostealers.
  • The MALFEX campaign has accumulated over 40,000 downloads.
  • The MALFEX campaign has been ongoing since August 2023.
  • Checkmarx identified 12 packages in the MALFEX campaign, with eight being malicious.
  • Three MALFEX packages (function-flag, function-color, cdn-img-fetch) were still installable as of October 1.
  • The 'function-flag' package has been malicious since July 2025 and has over 37,000 downloads.
  • OSV advisories exist for six MALFEX packages: tlxbnhd, tldriver, mxdriver, img-to-native, native-runner, and cdn-img-fetch.
  • Checkmarx identified three independent delivery paths in the MALFEX campaign.
🕒 2026-09-29 · new reporting from The Hacker News
  • 101 malicious npm packages were identified.
  • The packages were downloaded 490,000 times.
  • The packages exploit the 'Baileys' WhatsApp project.
  • The packages add developers' accounts to WhatsApp groups without consent.
  • The campaign is dubbed PhantomSub.
  • The campaign primarily advertises mobile games and applications.
  • Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko published a technical write-up.
  • 116,000 downloads occurred in the last 30 days.
  • SafeDep first identified the activity in August 2026.
🕒 2026-09-24 · new reporting from Hacker News Front Page
  • A malicious imitation of data wrangling software was reported to GitHub on August 31.
  • The malicious software used the original product's name and logo without permission.
  • The malicious .dmg file contained malware warnings on virustotal.com.
  • The malicious .dmg file's background image encouraged users to ignore malware warnings.
  • GitHub took 23 days to remove the malicious imitation software.
🕒 2026-09-23 · new reporting from The Hacker News
  • Go-based malware was distributed via two Go Modules and two Terraform providers.
  • This is the first time HashiCorp registry was used for malicious payload distribution.
  • The malicious Terraform providers are gocommunity-io/dockerd and kreuzwenker/docker.
  • The malicious Go modules are gocommunity.io/orderedbtree and gogets.dev/btreex.
  • The gocommunity-io/dockerd provider had 222 downloads.
  • The kreuzwenker/docker provider had 1,449 downloads.
  • The malware overlaps with Graphalgo, attributed to North Korean threat actors.
  • Attackers use social engineering on LinkedIn, Facebook, or job forums.
  • Attackers pose as non-existent Web3 companies.
  • Attackers ask developers to complete a coding task with a benign GitHub repository.
  • The GitHub repository introduces malicious behavior via an npm or PyPI dependency.
🕒 2026-09-22 · new reporting from The Hacker News
  • A malicious npm package, "tw-pkgprobe-7731," was discovered.
  • The package masquerades as a Twilio bug-bounty probe.
  • The package exfiltrates environment variables and Twilio account credentials.
  • The package was uploaded in mid-August 2026 by "twdepprobe7731."
  • 11 versions of the package were published in 45 minutes.
  • The npm user account "twdepprobe7731" no longer exists.
  • ReversingLabs researcher Lucija Valentić published a report on the package.
🕒 2026-09-22 · new reporting from The Hacker News, SecurityWeek
  • The 'indexed-btree' package was uploaded on June 18, 2026.
  • The 'indexed-btree' package was uploaded by user "charlessadler25".
  • The 'indexed-btree' package generated €230,933.57 in cryptocurrency.
  • The 'indexed-btree' package and GitHub repository are no longer available.
  • The malicious trigger was hidden in the package's JavaScript prototype code.
  • The threat actor created a legitimate-looking GitHub repository for 'indexed-btree'.
🕒 2026-09-20 · new reporting from BleepingComputer
  • The 'indexed-btree' npm package hides its payload in runtime code.
  • The 'indexed-btree' package impersonates the 'sorted-btree' library.
  • The 'indexed-btree' package has 2 million weekly downloads.
  • Attackers use a wallet holding 109 ETH.
  • GitHub announced npm security measures in June 2026.
  • The measures block dependency lifecycle scripts unless explicitly approved.
  • The measures prevent npm from automatically retrieving dependencies from Git repositories or remote URLs without permission.
🕒 2026-09-18 · new reporting from The Hacker News
  • 13 npm packages distribute the WeaselBiscuit JavaScript stealer.
  • WeaselBiscuit harvests Chrome extension storage.
  • WeaselBiscuit shares functional similarities with BeaverTail and OtterCookie malware.
  • WeaselBiscuit is a smaller, stripped-down version of BeaverTail and OtterCookie.
  • Paul McCarty (6mile) and Jenn Gile of OpenSourceMalware named the malware WeaselBiscuit.
🕒 2026-09-18 · new reporting from The Hacker News
  • A financially motivated threat actor developed and distributed PhantomRaven via npm.
  • PhantomRaven is a JavaScript-based information stealer.
  • The developer likely used an LLM to write the PhantomRaven malware.
  • CrowdStrike's Counter Adversary Operations published an analysis of PhantomRaven.
  • PhantomRaven was first flagged by Koi Security and DCODX in late October 2025.
  • PhantomRaven was distributed via a slopsquatting and typosquatted campaign.
  • Over 100 malicious packages were uploaded to npm in the PhantomRaven campaign.
  • PhantomRaven steals authentication tokens, CI/CD secrets, and GitHub credentials.
  • The attack used packages to retrieve a remote dynamic dependency from an external server.
  • The malware scans the developer environment for email addresses.
  • The malware gathers information about the CI/CD environment.
  • The malware collects a system fingerprint, including the public IP address.
🕒 2026-09-07 · new reporting from Hacker News Front Page
  • Researchers demonstrated a trusting-trust attack against the NixOS Linux distribution.
  • The attack manipulated the GNU strip utility.
  • The tampered strip propagated a payload through the build process.
  • The attack backdoored almost every binary in a complete graphical installer.
  • The research expands understanding of supply chain vulnerabilities beyond compilers to common build tools.
🕒 2026-09-07 · new reporting from InfoQ
  • vlt 1.0, a JavaScript package manager, has been released.
  • vlt was built by the original creators of npm.
  • vlt 1.0 offers phased installations.
  • vlt 1.0 includes a queryable dependency graph.
  • vlt 1.0 features hosted registries that block known malicious packages.
  • Darcy Clarke announced the vlt release on X.
  • vlt install downloads and extracts packages without executing anything.
  • vlt build runs approved scripts and blocks known malware.
  • vlt query is a dependency selector syntax.
🕒 2026-09-03 · new reporting from The Hacker News
  • Threat actors use Node.js runtime to deploy malicious payloads.
  • Attacks target government, technology, and hotel sectors since February 2026.
  • The technique bypasses signature-based detection by running malicious code as interpreted scripts.
  • A registry Run key entry relaunches the payload at every login.
  • One intrusion between March 23 and July 25, 2026, targeted an Asian technology company.
  • Attackers downloaded the official Node.js installer from nodejs[.]org.
  • The malicious implant establishes long-term access and retrieves commands using EtherHiding.
  • The Symantec Threat Hunter Team published a report on the discovery.
🕒 2026-08-26 · new reporting from BleepingComputer
  • Inf0stache first spotted the technique in July.
  • The 'china_airlines' npm package used a fake Cloudflare verification page.
🕒 2026-08-25 · new reporting from The Hacker News
  • 24 npm packages host fake Cloudflare CAPTCHA pages on unpkg mirrors.
  • The malicious npm packages redirect users to phishing sites.
  • OX Security researchers Moshe Siman Tov Bustan and Vitalii Chepurko discovered the campaign.
  • The npm packages are used as free phishing infrastructure.
  • The malware is a single HTML page inside the npm package.
  • The threat actor uses the npm registry and mirrors for validated storage of malware.
  • The campaign targets mirrors like unpkg.
🕒 2026-08-21 · new reporting from The Hacker News
  • 14 trojanized npm packages install the RedC2 4.0 Linux backdoor.
  • The packages masquerade as calendar and streak utilities.
  • The malicious module loads a bundled binary, marks it executable, and launches it.
  • No install hook function call is needed to execute the payload.
  • TrendAI published a report on the discovery.
🕒 2026-08-18 · new reporting from The Hacker News
  • The attack involved 16 typosquatted RubyGems packages.
  • The malicious packages steal browser credentials, crypto wallets, seed phrases, and Telegram data.
  • OpenSourceMalware discovered the activity on August 15, 2026.
  • OpenSourceMalware tracks the threat under the moniker StubMaker.
  • The packages were published by users "mod8rz41mje" (Riley Miller) and "rbq95bwt6q" (Alex Davis).

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~5 min · 3 stories · Oct 09

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

The npm package "tensorlake" version 0.5.144 was compromised to deliver the Shai-Hulud credential-stealing worm. This malware harvests credentials, exfiltrates secrets, establishes persistence, and executes remote code, posing a supply chain risk to developers using the package.

Cybersecurity researchers identified eight malicious npm packages, downloaded 40,767 times, that distribute the Overlord RAT and information stealers. The campaign, active since August 2023, targets Windows systems to compromise Discord, browsers, Telegram, and cryptocurrency wallets. This highlights ongoing software supply chain risks within the npm ecosystem.

A long-running NPM supply chain campaign, dubbed MALFEX, has accumulated over 40,000 downloads since August 2023 by distributing malicious packages containing the Overlord RAT and infostealers. Checkmarx identified 12 packages, with eight being malicious, and three still installable as of October 1, impacting primarily Windows systems. This campaign highlights ongoing software supply chain vulnerabilities and the need for vigilance in package dependencies.

Cybersecurity researchers identified 101 malicious npm packages, downloaded 490,000 times, that exploit the 'Baileys' WhatsApp project to add developers' accounts to WhatsApp groups without consent. This campaign, dubbed PhantomSub, uses various methods to subscribe users to attacker-controlled channels, primarily for advertising mobile games and applications.

GitHub took 23 days to remove a malicious imitation of data wrangling software, which used the original product's name and logo and contained malware. The removal occurred shortly after the issue gained visibility on Hacker News, highlighting a delay in GitHub's response to reported malicious content.

Cybersecurity researchers have identified Go-based malware distributed through two Go Modules and two Terraform providers hosted on the HashiCorp registry, marking the first time this centralized repository has been used for malicious payload distribution. This campaign, linked to North Korean threat actors, uses social engineering to trick developers into installing dependencies that deliver the malware, which has also been found in new malicious npm packages.

A malicious npm package, "tw-pkgprobe-7731," was discovered on the npm registry, masquerading as a Twilio bug-bounty probe. The package was designed to exfiltrate environment variables and Twilio account credentials like ACCOUNT_SID and AUTH_TOKEN from developer environments. This incident highlights supply chain risks in software development, particularly for developers integrating third-party services.

A malicious NPM package, 'indexed-btree', mimicking a legitimate B-tree utility, has accumulated 2 million weekly downloads as part of an ongoing supply chain attack. The attacker bypassed NPM's protections by hiding malicious code in the package's JavaScript prototype, collecting system information, and using a blockchain contract for command-and-control.

A malicious npm package, "indexed-btree," was discovered to hide its loader within application code, bypassing recent npm security changes that prevent automatic execution of lifecycle scripts. This tactic shift by threat actors indicates an adaptation to new security measures, impacting software supply chain security.

A malicious npm package, 'indexed-btree', has been identified bypassing GitHub's npm security measures by hiding its payload in runtime code rather than installation scripts. This method allows the malware to execute without triggering security approvals, collecting system details and exfiltrating data. The campaign highlights a new technique for supply chain attacks that evades current static analysis and taint-analysis tools.

Cybersecurity researchers discovered 13 npm packages distributing a new JavaScript stealer, WeaselBiscuit, which harvests Chrome extension storage across multiple operating systems. This malware shares functional similarities with North Korean-linked BeaverTail and OtterCookie strains but is a smaller, stripped-down version.

A financially motivated threat actor, claiming to be a bug bounty hunter, used an LLM to create and distribute the PhantomRaven JavaScript information stealer via npm. This malware collected developer credentials and system information, indicating a new method for supply chain attacks and potential misuse of LLMs in malware development.

vlt 1.0, a JavaScript package manager and registry, has been released, offering a drop-in replacement for npm with features like phased installations, a queryable dependency graph, and hosted registries that block known malicious packages. This release provides developers with enhanced security and auditing capabilities for managing JavaScript dependencies.

Researchers demonstrated a trusting-trust attack against the NixOS Linux distribution by manipulating the GNU strip utility, proving this type of attack is not limited to compilers. The tampered strip propagated a payload through the build process, backdooring almost every binary in a complete graphical installer. This research expands the understanding of supply chain vulnerabilities beyond compilers to common build tools.

Threat actors are exploiting the legitimate Node.js JavaScript runtime to deploy malicious payloads in targeted attacks against government, technology, and hotel sectors since February 2026. This method allows attackers to bypass signature-based detection by running malicious code as interpreted scripts within a trusted, signed executable, establishing long-term access and delivering various malware.

Threat actors are abusing npm and its mirroring platforms like UNPKG to host malicious HTML pages that impersonate Cloudflare CAPTCHAs, redirecting visitors to attacker-controlled websites. This technique uses npm as free, validated storage for phishing content, bypassing some security measures by serving malicious pages from legitimate domains.

Researchers discovered a campaign using 24 npm packages to host fake Cloudflare CAPTCHA pages on unpkg mirrors, redirecting users to phishing sites. This method exploits trusted npm infrastructure to deliver malicious content, posing a risk to users who encounter these mirrored links.

Cybersecurity researchers discovered 14 trojanized npm packages that install the RedC2 4.0 Linux backdoor, a cross-platform command-and-control framework. These packages masquerade as functional calendar and streak utilities but secretly deploy a Linux implant for post-exploitation activities. This development highlights ongoing supply chain risks in software development, particularly within the npm ecosystem.

Cybersecurity researchers discovered 16 typosquatted RubyGems packages designed to steal browser credentials, cryptocurrency wallets, seed phrases, and Telegram data from users. The campaign exploited RubyGems' package name reuse and unvalidated author fields, allowing attackers to republish malicious versions of yanked gems.

Nearly 800 malicious packages were published to the npm registry, distributing cross-platform malware that targets Windows, Mac, and Linux systems. This campaign uses a novel method of infection, instructing developers to use `require()` to load the packages, which then execute a downloader for a RAT and infostealer payload.

Security researchers disclosed an npm supply-chain attack that affected over 400 packages, including projects like Keyv and Cacheable, by using stolen developer credentials to publish malicious versions. This incident highlights a vulnerability where malware can operate within trusted workflows and even carry valid provenance attestations, bypassing traditional security checks.

GitHub's Dependabot now provides malware advisories for eight major package ecosystems, including PyPI, Maven, and RubyGems, by integrating data from OpenSSF's malicious-packages repository. This expansion significantly broadens Dependabot's capability to detect and alert users about malicious packages beyond its previous npm-only scope, enhancing software supply chain security for a wider range of developers.

An attacker compromised a developer's GitHub account to inject a credential-stealing worm into keyv and related npm packages, affecting over 868 packages and two billion monthly installs. This attack is significant because the malicious releases carried valid provenance signatures, demonstrating that attackers can exploit trusted supply chain mechanisms.

Cybersecurity researchers identified NullReceiver, an evolution of the EtherHiding C2 technique, which embeds command-and-control server IP addresses within the recipient addresses of empty Ethereum transfers. This method, linked to North Korean threat actors, was found in trojanized npm packages and makes C2 detection more difficult by avoiding smart contracts or transaction payload fields.

A supply chain attack named ChainDrop infected 440 NPM packages with over 2,200 malicious versions, impacting packages with over 500 million weekly downloads. The malware steals credentials from developer workstations and CI/CD environments, then uses them to self-propagate by publishing poisoned package versions and infecting GitHub repositories.

Self-propagating malware named 'ChainDrop' has infected over 1,300 packages on the npm registry, affecting popular utilities and packages from major organizations. The attack started by compromising a GitHub account and spread through malicious files pushed directly to project branches, leading to valid but poisoned package releases. This incident highlights a significant supply-chain vulnerability in the JavaScript ecosystem, potentially exposing developer and cloud credentials to attackers.

A credential-stealing npm worm, initially found in keyv@6.0.0, spread to hundreds of packages across multiple organizations on August 4, 2026. This worm uses a preinstall script to harvest sensitive credentials and can plant Claude Code and VS Code hooks, posing a significant supply chain security risk for developers and CI environments.

Cybersecurity researchers discovered 18 malicious npm packages targeting users of Alibaba developer tools with a cross-platform remote access trojan (RAT). The attack uses unscoped packages that impersonate private Alibaba packages to deliver the RAT through a dependency tree, primarily affecting developers in Chinese-speaking environments.

Beta versions of two npm packages, @joyfill/layouts and @joyfill/components, have been compromised to install a remote access trojan (RAT) linked to the DEV#POPPER malware family. The malicious code executes upon package import in Node.js and uses a multi-blockchain resolver structure for command and control, indicating a sophisticated supply chain attack.

Researchers found a trojanized version of Newtonsoft.Json on NuGet, designed to rig game results on Digitain. This trojan is notable for functioning normally for most users while targeting a specific system, representing a significant security threat in the package management ecosystem.

Five malicious AsyncAPI packages were uploaded to npm, delivering a remote access trojan. Over 2.25 million weekly downloads of these packages raise significant supply-chain security concerns in the software development community.

Four npm packages in the @asyncapi namespace have been compromised to distribute a multi-stage botnet malware identified as Miasma. This incident is significant as it highlights vulnerabilities in widely used packages and poses risks for credential theft and other malicious activities.

Jscrambler's NPM package faced a supply chain attack, compromising multiple versions that included malicious code. The affected packages exposed sensitive data from developers' machines, raising concerns about the security of open-source dependencies.

A compromised version of the Jscrambler npm package was discovered to contain information-stealing malware that executed during the installation process and was downloaded nearly 1,500 times. Jscrambler quickly deprecated the affected releases and implemented additional security measures following the incident, which was attributed to compromised npm publishing credentials.

The jscrambler npm package version 8.14.0 was compromised to execute an infostealer upon installation. This malicious version, published on July 11, 2026, targets developers' sensitive information, including cloud credentials and cryptocurrency wallets, escalating security risks for users.