Advertisement
Node.js Abuse: Attackers Deploy Malware via Trusted Runtime
Threat actors are leveraging Node.js as a signed, trusted tool to deploy various malicious payloads, evading detection in targeted attacks since February 2026.
Critical Type Confusion in isolated-vm Leads to Host RCE
A critical type confusion vulnerability in the Node.js isolated-vm library allows remote code execution on the host system via V8 Isolates.
Compromised Joyfill npm Packages Deliver DEV#POPPER RAT
Beta versions of @joyfill/layouts and @joyfill/components npm packages compromised to deliver a DEV#POPPER RAT upon import. Node.js users at risk.
North Korean Actors Use SVG Steganography to Deliver OtterCookie
North Korean threat actors are hiding OtterCookie malware in SVG flag images within fake coding tests to target developers and steal cryptocurrency.
Jscrambler npm Package Backdoored with Infostealer Malware
A malicious version of the Jscrambler npm package, 5.0.0-beta-1, was backdoored with infostealer malware, affecting 1,500 downloads. Immediate action needed.
npm 12 Security: Default Script Execution Changes to Mitigate Supply Chain Attacks
npm 12 introduces a critical change: 'npm install' will no longer run dependency scripts by default, significantly reducing software supply chain risks.
Advertisement
Analysis of Cross-Platform NPM Stealer Using Discord Webhooks
Technical teardown of an obfuscated Node.js infostealer targeting Discord tokens, crypto wallets, and browser credentials via cross-platform scripts.
vm2 Node.js Library RCE: Multiple Sandbox Escape Vulnerabilities
Discovery of a dozen critical vulnerabilities in the vm2 Node.js library allows for sandbox escape and RCE. Learn how to mitigate these security risks now.
CVE-2023-29017: Critical vm2 Sandbox Escape Leads to Host RCE
Technical analysis of CVE-2023-29017 in the vm2 Node.js library. Learn how attackers escape the sandbox for remote code execution and how to patch.
Axios npm Supply Chain Attack: Malicious Payloads and Mitigation
Axios npm versions 1.14.1 and 0.30.4 compromised via a malicious dependency injecting remote access trojans. Learn how to detect and remediate this threat.
North Korean Social Engineering Targets Node.js Maintainers
North Korean threat actors use social engineering and malicious npm packages to target high-profile Node.js maintainers in a sophisticated supply chain campaign.
North Korean Malicious npm Packages: Detecting Contagious Interview
North Korean actors published 26 malicious npm packages using Pastebin as a C2 dead drop resolver in a new Contagious Interview campaign iteration.