Security researchers at StepSecurity have issued an emergency warning regarding a high-stakes supply chain attack targeting axios,...
Node.js
Security researchers have disclosed two critical vulnerabilities in n8n, the popular fair-code workflow automation platform used by...
The Node.js project has released a critical sweep of security updates across its 20.x, 22.x, 24.x, and...
With over 18 million downloads, basic-ftp is a cornerstone utility for Node.js developers, offering a robust, Promise-based...
A high-severity vulnerability has been discovered in Axios, the immensely popular HTTP client used by millions of...
A perfect storm of missing checks has led to a maximum-severity vulnerability in SandboxJS, a library designed...
A critical security vulnerability has been unearthed in vm2, a highly popular sandbox library for Node.js used...
Developers using the popular binary-parser library for Node.js are being urged to update their dependencies immediately following...
The Node.js maintainers have kicked off the new year with a critical security release, addressing a trio...
A critical vulnerability has been discovered in jsPDF, one of the most popular JavaScript libraries for generating...
A critical security vulnerability has been discovered in AdonisJS, a popular full-stack Node.js web framework known for...
A new, sophisticated malware campaign is sweeping across the internet, leveraging a recently disclosed vulnerability to install...
A high-severity vulnerability has been uncovered in systeminformation, a massively popular Node.js library used by millions of...
A sophisticated malware campaign has infiltrated the indie gaming platform Itch.io, using deceptive “game update” lures to...
A new report from NTT Security Japan has spotlighted an evolved malware family known as OtterCandy, attributed...
A new report from Cisco Talos has exposed a malware campaign linked to Famous Chollima, a North...
A critical-severity vulnerability has been disclosed in Happy DOM, a popular JavaScript package used to emulate web...
The Axios project has released a security advisory for a newly discovered vulnerability affecting its popular promise-based...
Socket has detected a large-scale supply chain attack in progress targeting the npm ecosystem. The account of...
A critical security vulnerability has been disclosed in sha.js, a widely used JavaScript library that implements the...