Skip to main content
← All Articles

Tag

#NPM

75 articles

Advertisement

INFO
Supply Chain

npm 12 Security: Default Script Execution Changes to Mitigate Supply Chain Attacks

npm 12 introduces a critical change: 'npm install' will no longer run dependency scripts by default, significantly reducing software supply chain risks.

Runtime Rebel Intel
4 min read · Jun 13, 2026
GitHub to Disable npm Install Scripts by Default in Version 12
MEDIUM
Supply Chain

GitHub to Disable npm Install Scripts by Default in Version 12

GitHub announces breaking changes for npm v12, disabling install scripts by default to prevent malicious code execution and enhance supply chain security.

Runtime Rebel Intel
4 min read · Jun 11, 2026
npm Supply Chain Attack: IronWorm and Miasma Malware Analysis
HIGH
Supply Chain

npm Supply Chain Attack: IronWorm and Miasma Malware Analysis

Threat actors target npm developers with the IronWorm info stealer and Miasma worm, utilizing eBPF rootkits to exfiltrate secrets and ensure persistence.

Runtime Rebel Intel
3 min read · Jun 5, 2026
IronWorm: Rust-Written Malware Hits npm Supply Chain Developers
HIGH
Supply Chain

IronWorm: Rust-Written Malware Hits npm Supply Chain Developers

Analysis of the Rust-written IronWorm malware targeting npm supply chain developers.

Runtime Rebel Intel
5 min read · Jun 5, 2026
HIGH
Supply Chain

IronWorm Malware: 36 npm Packages Identified in Supply Chain Attack

Security researchers discover a campaign delivering IronWorm infostealer malware via 36 malicious npm packages using preinstall script execution hooks.

Runtime Rebel Intel
3 min read · Jun 4, 2026
HIGH
Supply Chain

Red Hat npm Supply Chain Compromise: Miasma Steals Dev Credentials

Over 30 Red Hat npm packages under @redhat-cloud-services were compromised in a supply chain attack distributing Miasma malware to steal developer credentials.

Runtime Rebel Intel
5 min read · Jun 2, 2026

Advertisement

Miasma Supply Chain Attack: Defending Red Hat npm Environments
HIGH
Supply Chain

Miasma Supply Chain Attack: Defending Red Hat npm Environments

Analysis of the Miasma supply chain attack targeting Red Hat npm packages with credential-stealing worms. Technical details and mitigation guide for SOC teams.

Runtime Rebel Intel
3 min read · Jun 1, 2026
Malicious npm Package Targets Claude AI User Data — Technical Analysis
HIGH
Supply Chain

Malicious npm Package Targets Claude AI User Data — Technical Analysis

Researchers discover mouse5212-super-formatter, a malicious npm package designed to exfiltrate sensitive files from Claude AI user directories.

Runtime Rebel Intel
3 min read · May 27, 2026
Shai-Hulud Campaign: TeamPCP Targets Open-Source Supply Chain
HIGH
Supply Chain

Shai-Hulud Campaign: TeamPCP Targets Open-Source Supply Chain

Analysis of the Shai-Hulud campaign by TeamPCP, detailing their open-source supply chain attacks, TTPs, and critical mitigation strategies.

Runtime Rebel Intel
5 min read · May 26, 2026
HIGH
Supply Chain

TeamPCP Supply Chain Attack Targets Microsoft SDKs and GitHub

TeamPCP expands its supply chain campaign to trojanize official Microsoft Python SDKs and infiltrate GitHub, requiring immediate dependency audits.

Runtime Rebel Intel
3 min read · May 25, 2026
TrapDoor Campaign: Detecting Cross-Ecosystem Supply Chain Attacks
HIGH
Supply Chain

TrapDoor Campaign: Detecting Cross-Ecosystem Supply Chain Attacks

The TrapDoor campaign targets npm, PyPI, and Crates.io with over 384 malicious versions designed to exfiltrate developer credentials and sensitive data.

Runtime Rebel Intel
4 min read · May 25, 2026
npm Staged Publishing: New 2FA Controls Prevent Supply Chain Attacks
MEDIUM
Supply Chain

npm Staged Publishing: New 2FA Controls Prevent Supply Chain Attacks

GitHub introduces staged publishing for npm, requiring manual 2FA approval for package releases to mitigate malicious automated updates and account takeovers.

Runtime Rebel Intel
4 min read · May 23, 2026
HIGH
Malware

Analysis of Cross-Platform NPM Stealer Using Discord Webhooks

Technical teardown of an obfuscated Node.js infostealer targeting Discord tokens, crypto wallets, and browser credentials via cross-platform scripts.

Runtime Rebel Intel
4 min read · May 22, 2026
HIGH
Supply Chain

GitHub Repository Breach Linked to TanStack Supply Chain Attack

GitHub confirms the breach of 3,800 internal repositories via a compromised VS Code extension linked to the TanStack npm supply chain attack.

Runtime Rebel Intel
4 min read · May 21, 2026
HIGH
Data Breach

Grafana Breach After TanStack Attack: Token Rotation Failure

Grafana suffered a data breach due to a GitHub workflow token not rotated after the TanStack npm supply-chain attack, impacting user data. Learn the details.

Runtime Rebel Intel
4 min read · May 20, 2026
HIGH
Supply Chain

320+ @antv NPM Packages Compromised in Mini Shai-Hulud Attack

A maintainer account compromise has led to a major supply chain attack against Alibaba’s @antv NPM namespace, impacting over 320 visualization packages.

Runtime Rebel Intel
4 min read · May 20, 2026
HIGH
Supply Chain

TeamPCP Jenkins Plugin Compromise and Mini Shai-Hulud Worm Analysis

TeamPCP escalates its supply chain campaign with a confirmed Jenkins plugin compromise and a self-spreading worm targeting the npm and PyPI ecosystems.

Runtime Rebel Intel
3 min read · May 18, 2026
HIGH
Supply Chain

Shai-Hulud Infostealer Surfaces in Malicious npm Package Campaign

Leaked Shai-Hulud malware is targeting Node.js developers via malicious npm packages, exfiltrating sensitive data and credentials to Telegram-based C2.

Runtime Rebel Intel
4 min read · May 18, 2026
Microsoft Exchange Zero-Day and npm Supply Chain Worm Under Active Use
CRITICAL
Threat Intel

Microsoft Exchange Zero-Day and npm Supply Chain Worm Under Active Use

Critical security briefing on the active exploitation of an Exchange Server zero-day, npm supply chain worms, and Cisco network control vulnerabilities.

Runtime Rebel Intel
3 min read · May 18, 2026
Developer Workstations: The New Front in Software Supply Chain Attacks
HIGH
Supply Chain

Developer Workstations: The New Front in Software Supply Chain Attacks

A surge in attacks targeting npm, PyPI, and Docker Hub highlights a shift toward stealing developer credentials and API keys from workstations and CI/CD pipelines.

Runtime Rebel Intel
4 min read · May 18, 2026
HIGH
Supply Chain

OpenAI Breach: TanStack Supply Chain Attack Impacts Employee Devices

OpenAI confirms two employee devices compromised in a TanStack supply chain attack affecting npm and PyPI packages, prompting certificate rotation.

Runtime Rebel Intel
5 min read · May 14, 2026
Malicious node-ipc Versions Compromise Developer Secrets via Supply Chain
HIGH
Supply Chain

Malicious node-ipc Versions Compromise Developer Secrets via Supply Chain

Three versions of the node-ipc npm package (9.1.6, 9.2.3, 12.0.1) contain stealer/backdoor functionality targeting developer secrets. Urgent update advised.

Runtime Rebel Intel
4 min read · May 14, 2026
HIGH
Supply Chain

Shai-Hulud Supply Chain Attack: Malicious npm and Mistral Packages

The Shai-Hulud campaign targets developers with over 300 signed npm and PyPI packages impersonating TanStack and Mistral to steal sensitive credentials.

Runtime Rebel Intel
4 min read · May 12, 2026
Mini Shai-Hulud Worm Compromises TanStack and Mistral AI Packages
HIGH
Supply Chain

Mini Shai-Hulud Worm Compromises TanStack and Mistral AI Packages

TeamPCP actor compromises major npm and PyPI packages including TanStack and Mistral AI via the Mini Shai-Hulud worm, deploying profiling malware.

Runtime Rebel Intel
4 min read · May 12, 2026