Skip to main content
← All Articles

Tag

#NPM

75 articles

Advertisement

MEDIUM
Supply Chain

Hackers Abuse npm Mirrors to Host Phishing Redirects

Threat actors exploit npm and its mirroring platforms like UNPKG to host malicious HTML pages, impersonating Cloudflare CAPTCHAs for phishing redirects.

Runtime Rebel Intel
5 min read · Aug 26, 2026
Trojanized npm Packages Deliver AI-Powered RedC2 4.0 Linux Backdoor
HIGH
Supply Chain

Trojanized npm Packages Deliver AI-Powered RedC2 4.0 Linux Backdoor

Malicious npm packages deliver RedC2 4.0 Linux backdoor, featuring AI-assisted command and control for advanced post-exploitation.

Runtime Rebel Intel
4 min read · Aug 22, 2026
npm Supply Chain Attacks: Shai-Hulud, Miasma, and CI/CD Compromises
HIGH
Supply Chain

npm Supply Chain Attacks: Shai-Hulud, Miasma, and CI/CD Compromises

The npm ecosystem faces escalating supply chain attacks like Shai-Hulud and Miasma RAT, leading to credential theft and widespread package compromise.

Runtime Rebel Intel
5 min read · Aug 8, 2026
Critical npm Supply Chain Attack Delivers Cross-Platform RAT/Infostealer
HIGH
Supply Chain

Critical npm Supply Chain Attack Delivers Cross-Platform RAT/Infostealer

Critical npm supply chain attack involving nearly 800 malicious packages delivers WEL1DROPPER RAT and infostealer to Windows, macOS, and Linux users.

Runtime Rebel Intel
5 min read · Aug 8, 2026
ChainDrop npm Worm: Self-Propagating Software Supply Chain Threat
MEDIUM
Supply Chain

ChainDrop npm Worm: Self-Propagating Software Supply Chain Threat

Analyze the ChainDrop self-propagating npm worm infecting major packages, harvesting credentials from memory, and compromising CI/CD pipelines.

Runtime Rebel Intel
3 min read · Aug 7, 2026
HIGH
Supply Chain

Keyv npm Supply-Chain Attack: Worm Infection and Dead-Man Switch

Analyze the Keyv/cacheable npm supply-chain worm, its AI agent execution vectors, and why immediate credential revocation can trigger payloads.

Runtime Rebel Intel
3 min read · Aug 6, 2026

Advertisement

HIGH
Supply Chain

ChainDrop npm Supply Chain Attack Steals Developer Credentials

Massive ChainDrop npm supply chain attack compromises over 1,300 packages, stealing developer and cloud credentials through malicious preinstall scripts.

Runtime Rebel Intel
4 min read · Aug 4, 2026
Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Users
HIGH
Supply Chain

Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Users

Discover how 18 malicious npm packages target Alibaba developer tools with a cross-platform remote access trojan in a supply chain attack.

Runtime Rebel Intel
3 min read · Aug 4, 2026
CRITICAL
Supply Chain

North Korean Hackers Exploit npm Supply Chain: Debug & Chalk Under Attack

Amazon links North Korean hackers to supply chain attacks on popular npm packages Debug and Chalk, highlighting nation-state threat to open-source ecosystems.

Runtime Rebel Intel
4 min read · Jul 30, 2026
Compromised Joyfill npm Packages Deliver DEV#POPPER RAT
HIGH
Supply Chain

Compromised Joyfill npm Packages Deliver DEV#POPPER RAT

Beta versions of @joyfill/layouts and @joyfill/components npm packages compromised to deliver a DEV#POPPER RAT upon import. Node.js users at risk.

Runtime Rebel Intel
5 min read · Jul 29, 2026
Malicious Vite npm Packages Deliver RAT via Blockchain C2
HIGH
Supply Chain

Malicious Vite npm Packages Deliver RAT via Blockchain C2

Seven malicious npm packages target Vite frontend projects. Dubbed ViteVenom, this software supply chain attack uses a four-tier blockchain C2 to deploy a RAT.

Runtime Rebel Intel
4 min read · Jul 17, 2026
HIGH
Supply Chain

AsyncAPI npm packages infected with credential-stealing malware

Five malicious versions of AsyncAPI npm packages deployed a credential-stealing remote access trojan via a supply chain attack. Learn detection and mitigation.

Runtime Rebel Intel
5 min read · Jul 15, 2026
HIGH
Supply Chain

Jscrambler NPM Packages Poisoned in Supply Chain Attack

Attackers poisoned official Jscrambler NPM packages to distribute cross-platform credential stealers. Learn the impact and how to remediate the threat.

Runtime Rebel Intel
4 min read · Jul 14, 2026
HIGH
Supply Chain

Jscrambler npm Package Backdoored with Infostealer Malware

A malicious version of the Jscrambler npm package, 5.0.0-beta-1, was backdoored with infostealer malware, affecting 1,500 downloads. Immediate action needed.

Runtime Rebel Intel
4 min read · Jul 13, 2026
jscrambler 8.14.0 Compromised: Rust Infostealer Supply Chain Attack
HIGH
Supply Chain

jscrambler 8.14.0 Compromised: Rust Infostealer Supply Chain Attack

The jscrambler 8.14.0 npm release was compromised with a malicious preinstall hook dropping a cross-platform Rust infostealer. Mitigate the threat now.

Runtime Rebel Intel
4 min read · Jul 11, 2026
Injective Labs npm Package Compromise Steals Crypto Keys
HIGH
Supply Chain

Injective Labs npm Package Compromise Steals Crypto Keys

Critical supply chain attack compromises Injective Labs SDK on GitHub, distributing malicious npm package `@injectivelabs/sdk-ts@1.20.21` to steal crypto wallet keys.

Runtime Rebel Intel
4 min read · Jul 10, 2026
HIGH
Supply Chain

Injective SDK npm Compromise: Crypto Wallet Stealer Detected

A malicious version of the Injective SDK (injective-js) on npm was published via a GitHub compromise, deploying a crypto wallet stealer. Developers are at risk.

Runtime Rebel Intel
4 min read · Jul 10, 2026
npm 12 Enhances Supply Chain Security by Disabling Install Scripts
INFO
Supply Chain

npm 12 Enhances Supply Chain Security by Disabling Install Scripts

npm version 12 introduces critical security defaults, disabling install scripts and deprecating GATs, significantly mitigating JavaScript supply chain risks.

Runtime Rebel Intel
4 min read · Jul 9, 2026
HIGH
Supply Chain

Fake Paysafe/Skrill SDKs on npm & PyPI Steal Credentials

Malicious packages impersonating Paysafe and Skrill SDKs on npm and PyPI platforms are stealing credentials from developers and users. Threat intelligence analysis.

Runtime Rebel Intel
4 min read · Jul 8, 2026
PolinRider: North Korean Hackers Push 108 Malicious Packages
HIGH
Supply Chain

PolinRider: North Korean Hackers Push 108 Malicious Packages

Analysis of the PolinRider campaign where North Korean actors published 108 malicious packages and extensions across npm, Go, and Chrome ecosystems.

Runtime Rebel Intel
4 min read · Jul 4, 2026
N. Korea-Linked npm Packages Mimic Rollup Polyfills for Data Theft
HIGH
Supply Chain

N. Korea-Linked npm Packages Mimic Rollup Polyfills for Data Theft

North Korea-linked actors use malicious npm packages ('rollup-packages-polyfill-core', 'rollup-runtime-polyfill-core') to steal developer secrets, mimicking Rollup…

Runtime Rebel Intel
5 min read · Jul 3, 2026
Malicious npm Packages Impersonate PostCSS to Deliver Windows RAT
HIGH
Supply Chain

Malicious npm Packages Impersonate PostCSS to Deliver Windows RAT

Security researchers uncover malicious npm packages such as postcss-minify-selector-parser delivering Windows RATs via supply chain attacks. Audit your builds.

Runtime Rebel Intel
3 min read · Jun 23, 2026
HIGH
Supply Chain

North Korean Sapphire Sleet Compromises 140+ Mastra AI npm Packages

Microsoft attributes the Mastra AI supply chain attack to Sapphire Sleet (BlueNoroff), involving 140+ malicious npm packages targeting AI developers.

Runtime Rebel Intel
3 min read · Jun 20, 2026
NastyC2 npm Packages, AI Abuse & macOS Threats Identified
HIGH
Threat Intel

NastyC2 npm Packages, AI Abuse & macOS Threats Identified

Analysis of NastyC2 npm supply chain attacks, Claude chat abuse for malware, memory-resident macOS threats, and device-code phishing.

Runtime Rebel Intel
4 min read · Jun 18, 2026