A high-severity vulnerability has been uncovered in systeminformation, a massively popular Node.js library used by millions of...
npm
CERT/CC has issued a warning about a high-impact cryptographic vulnerability in the Forge JavaScript library — also...
The Socket Threat Research Team has uncovered a highly coordinated malware campaign operating across seven npm packages,...
In one of the largest open-source supply chain incidents ever recorded, Amazon Inspector security researchers have uncovered...
Researchers at Datadog Security Research have uncovered a major supply-chain compromise in the npm ecosystem involving 17...
Koi Security has uncovered a massive supply-chain campaign dubbed PhantomRaven, which has silently infected the npm ecosystem...
The Socket Threat Research Team has uncovered an extensive supply chain attack targeting the npm ecosystem, involving...
The Socket Threat Research Team has uncovered a growing trend among malicious package developers: leveraging Discord webhooks...
The Socket Threat Research Team has sounded the alarm on an escalating wave of malicious npm activity...
Socket’s Threat Research Team has uncovered a massive supply-chain abuse campaign leveraging npm’s public registry and unpkg.com’s...
The Socket Threat Research Team has uncovered a new malware campaign hiding inside an npm package called...
The malicious supply chain campaign dubbed “Shai-Hulud” has struck again, this time compromising multiple npm packages published...
The Socket Research Team has uncovered a large-scale supply chain attack on the npm ecosystem, with more...
Socket has detected a large-scale supply chain attack in progress targeting the npm ecosystem. The account of...
Researchers from ReversingLabs have discovered two malicious npm packages leveraging Ethereum smart contracts to conceal and deliver...
Researchers from Socket’s Threat Research Team have uncovered a dangerous npm package, nodejs-smtp, that impersonates the widely...
The StepSecurity research team has issued a warning about a large-scale supply chain attack involving the popular...
A newly disclosed vulnerability in the widely used tar-fs NPM package has raised alarms across the software...
A recent investigation by ReversingLabs has revealed how a targeted phishing attack led to the compromise of...
Socket’s Threat Research Team has uncovered two malicious npm packages—naya-flore and nvlore-hsc—designed to target developers building WhatsApp...