#npm

65 posts · Last used 20d

Popular npm Package With 150K+ Weekly Downloads Hit by Credential-Stealing Supply-Chain Worm Indicators extracted from public reporting. Source: https://research.jfrog.com/post/shai-hulud-trinitite/ Pulse ID: 6a956bc92f739d8a0e243dd2 Pulse Link: https://otx.alienvault.com/pulse/6a956bc92f739d8a0e243dd2 Pulse Author: CyberHunter_NL Created: 2026-08-31 11:55:53 Be advised, this data is unverified and should be considered preliminary. Always do further verification. #CyberSecurity #HTTP #HTTPS #InfoSec #NPM #OTX #OpenThreatExchange #RCE #Worm #bot #CyberHunter_NL
0
0
0
0
Der GitHub-Account des Maintainers der Key-Value-Datenbank #keyv wurde kompromittiert Durch die Shai-Hulud-Lieferkettenattacke sind über 440 #npm-Pakete betroffen mit rund 2 Milliarden Downloads monatlich Der Schadcode startet automatisch bei Installation und sucht nach Zugangsdaten https://www.heise.de/news/Lieferketten-Angriff-auf-keyv-Shai-Hulud-Wurm-infiziert-mehr-als-440-npm-Pakete-11403078.html?seite=all
2
0
4
0
Replying to
Scherz beiseite, ich benutze natürlich "--ignore-scripts" mit ganz wenigen Ausnahmen und jetzt habe ich entdeckt, dass es seit npm 11 auch eine "min-release-age" Option gibt, mit der man neue Package-Versionen erst mal ein paar Tage abhängen lassen kann. #npm #security #itsec
0
0
0
0
NPM account takeovers via expired maintainer domains You don't need to exploit npm to poison it. Buy the expired email domain behind a maintainer's account, reset the password, and the package is yours. We scanned 2.1 million packages, extracted 6.7 million maintainer emails, and found 675 expired domains leaving 2,843 packages open to takeover. Those packages sit under 257,000+ dependent repos and 93,000 downstream packages. One lapsed domain renewal, a supply chain full of blast radius. https://laburity.com/research-npm-account-takeovers/ #SupplyChainSecurity #npm #AccountTakeover #AppSec #Laburity
0
0
0
0

That's why you should migrate to #NPM v12, it prevents exactly this kind of attack: https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack

Every package in the family received two new files, setup.mjs and Math_Symbol.js, along with a "preinstall": "node setup.mjs" entry added to each package.json. Anyone who ran npm install against an affected version would have had setup.mjs execute automatically before their install completed.

0
2
1
0
🤖 ChainDrop: massive npm supply-chain attack. Worm compromised 1,300+ packages (~2B monthly downloads) after hijacking the Keyv maintainer's GitHub account; releases kept valid provenance via legit GitHub Actions. setup.mjs auto-runs on npm install and deploys a Bun-based infostealer. 🔗 https://www.bleepingcomputer.com/news/security/massive-chaindrop-npm-supply-chain-attack-infects-hundreds-of-packages/ #SupplyChain #npm #Malware #InfoSec
0
0
0
0
New. Socket: Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack https://socket.dev/blog/popular-npm-packages-in-the-keyv-and-cacheable-namespaces-compromised-in-active-supply-chain @SocketSecurity@fosstodon.org More: The Hacker news: Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks https://thehackernews.com/2026/08/keyv-linked-npm-worm-poisons-hundreds.html @thehackernews@social.tchncs.de #infosec #npm #threatresearch #JavaScript
0
0
0
0

Hey, hey, it's been a long time since the last huge supply chain attack (what about AUR? it's for nerds). NPM Supply Chain Attack returned again, this time infecting more than 444 packages with accumulation of 2B (yeah B for billion) downloads. The malware used is Shai-hulud again, but this time, the culprit is Copycat of TeamPCP.

What should you do?

  • Check if you are affected, if so, downgrade your library version
  • Rotate your keys and do 2FA
  • Search for infected accounts in your system, if there is one, remove it... or kill it with cold blood.

More details: https://www.ox.security/blog/a-new-infostealer-worm-hits-npm-affecting-keyv-and-cacheable/

#cybersecurity #infosec #security #supplychainsecurity #supplychain #npm#shaihuludmalware

0
0
0
0
The secure way to release an npm package in 2026. @sitnik_en@mastodon.social breaks down how supply chain attacks now run semi-automatically, compromising hundreds of packages a day, and frames security as raising the cost for attackers rather than chasing perfection. The quick wins, most doable in under a day, include npm Trusted and Staged Publishing, org-wide 2FA, admin-only tags, CI actions pinned to SHA, and a 3-day dependency cooldown. #npm #security https://evilmartians.com/chronicles/the-secure-way-to-release-an-npm-package
1
0
0
0