Skip to main content
← All Articles

Tag

#npm

44 articles

Advertisement

SU
CRITICAL
Supply Chain

Red Hat npm Supply Chain Compromise: Miasma Steals Dev Credentials

Over 30 Red Hat npm packages under @redhat-cloud-services were compromised in a supply chain attack distributing Miasma malware to steal developer credentials.

Runtime Rebel Intel
5 min read·Jun 2, 2026
Miasma Supply Chain Attack: Defending Red Hat npm Environments
CRITICAL
Supply Chain

Miasma Supply Chain Attack: Defending Red Hat npm Environments

Analysis of the Miasma supply chain attack targeting Red Hat npm packages with credential-stealing worms. Technical details and mitigation guide for SOC teams.

Runtime Rebel Intel
3 min read·Jun 1, 2026
Malicious npm Package Targets Claude AI User Data — Technical Analysis
HIGH
Supply Chain

Malicious npm Package Targets Claude AI User Data — Technical Analysis

Researchers discover mouse5212-super-formatter, a malicious npm package designed to exfiltrate sensitive files from Claude AI user directories.

Runtime Rebel Intel
3 min read·May 27, 2026
Shai-Hulud Campaign: TeamPCP Targets Open-Source Supply Chain
HIGH
Supply Chain

Shai-Hulud Campaign: TeamPCP Targets Open-Source Supply Chain

Analysis of the Shai-Hulud campaign by TeamPCP, detailing their open-source supply chain attacks, TTPs, and critical mitigation strategies.

Runtime Rebel Intel
5 min read·May 26, 2026
TrapDoor Campaign: Detecting Cross-Ecosystem Supply Chain Attacks
HIGH
Supply Chain

TrapDoor Campaign: Detecting Cross-Ecosystem Supply Chain Attacks

The TrapDoor campaign targets npm, PyPI, and Crates.io with over 384 malicious versions designed to exfiltrate developer credentials and sensitive data.

Runtime Rebel Intel
4 min read·May 25, 2026
npm Staged Publishing: New 2FA Controls Prevent Supply Chain Attacks
MEDIUM
Supply Chain

npm Staged Publishing: New 2FA Controls Prevent Supply Chain Attacks

GitHub introduces staged publishing for npm, requiring manual 2FA approval for package releases to mitigate malicious automated updates and account takeovers.

Runtime Rebel Intel
3 min read·May 23, 2026
MA
HIGH
Malware

Analysis of Cross-Platform NPM Stealer Using Discord Webhooks

Technical teardown of an obfuscated Node.js infostealer targeting Discord tokens, crypto wallets, and browser credentials via cross-platform scripts.

Runtime Rebel Intel
3 min read·May 22, 2026
SU
HIGH
Supply Chain

GitHub Repository Breach Linked to TanStack Supply Chain Attack

GitHub confirms the breach of 3,800 internal repositories via a compromised VS Code extension linked to the TanStack npm supply chain attack.

Runtime Rebel Intel
4 min read·May 21, 2026
DA
HIGH
Data Breach

Grafana Breach After TanStack Attack: Token Rotation Failure

Grafana suffered a data breach due to a GitHub workflow token not rotated after the TanStack npm supply-chain attack, impacting user data. Learn the details.

Runtime Rebel Intel
4 min read·May 20, 2026
SU
HIGH
Supply Chain

320+ @antv NPM Packages Compromised in Mini Shai-Hulud Attack

A maintainer account compromise has led to a major supply chain attack against Alibaba’s @antv NPM namespace, impacting over 320 visualization packages.

Runtime Rebel Intel
3 min read·May 20, 2026
SU
HIGH
Supply Chain

TeamPCP Jenkins Plugin Compromise and Mini Shai-Hulud Worm Analysis

TeamPCP escalates its supply chain campaign with a confirmed Jenkins plugin compromise and a self-spreading worm targeting the npm and PyPI ecosystems.

Runtime Rebel Intel
3 min read·May 18, 2026
SU
HIGH
Supply Chain

Shai-Hulud Infostealer Surfaces in Malicious npm Package Campaign

Leaked Shai-Hulud malware is targeting Node.js developers via malicious npm packages, exfiltrating sensitive data and credentials to Telegram-based C2.

Runtime Rebel Intel
4 min read·May 18, 2026