In one of the largest open-source supply chain incidents ever recorded, Amazon Inspector security researchers have uncovered...
npm
Researchers at Datadog Security Research have uncovered a major supply-chain compromise in the npm ecosystem involving 17...
Koi Security has uncovered a massive supply-chain campaign dubbed PhantomRaven, which has silently infected the npm ecosystem...
The Socket Threat Research Team has uncovered an extensive supply chain attack targeting the npm ecosystem, involving...
The Socket Threat Research Team has uncovered a growing trend among malicious package developers: leveraging Discord webhooks...
The Socket Threat Research Team has sounded the alarm on an escalating wave of malicious npm activity...
Socketβs Threat Research Team has uncovered a massive supply-chain abuse campaign leveraging npmβs public registry and unpkg.comβs...
The Socket Threat Research Team has uncovered a new malware campaign hiding inside an npm package called...
The malicious supply chain campaign dubbed βShai-Huludβ has struck again, this time compromising multiple npm packages published...
The Socket Research Team has uncovered a large-scale supply chain attack on the npm ecosystem, with more...
Socket has detected a large-scale supply chain attack in progress targeting the npm ecosystem. The account of...
Researchers from ReversingLabs have discovered two malicious npm packages leveraging Ethereum smart contracts to conceal and deliver...
Researchers from Socketβs Threat Research Team have uncovered a dangerous npm package, nodejs-smtp, that impersonates the widely...
The StepSecurity research team has issued a warning about a large-scale supply chain attack involving the popular...
A newly disclosed vulnerability in the widely used tar-fs NPM package has raised alarms across the software...
A recent investigation by ReversingLabs has revealed how a targeted phishing attack led to the compromise of...
Socket’s Threat Research Team has uncovered two malicious npm packagesβnaya-flore and nvlore-hscβdesigned to target developers building WhatsApp...
Veracode Threat Research has released an update on an ongoing North Korean cyber-espionage campaign that is actively...
In a recently expose, Sonatype reveals a covert cyberespionage campaign orchestrated by the North Korea-linked Lazarus Group,...
The lightweight JavaScript utility library is is a widely popular project on the NPM platform, boasting over...