Skip to main content
← All Articles

Tag

#npm

52 articles

Advertisement

SU
HIGH
Supply Chain

Shai-Hulud Supply Chain Attack: Malicious npm and Mistral Packages

The Shai-Hulud campaign targets developers with over 300 signed npm and PyPI packages impersonating TanStack and Mistral to steal sensitive credentials.

Runtime Rebel Intel
3 min read·May 12, 2026
Mini Shai-Hulud Worm Compromises TanStack and Mistral AI Packages
CRITICAL
Supply Chain

Mini Shai-Hulud Worm Compromises TanStack and Mistral AI Packages

TeamPCP actor compromises major npm and PyPI packages including TanStack and Mistral AI via the Mini Shai-Hulud worm, deploying profiling malware.

Runtime Rebel Intel
4 min read·May 12, 2026
TeamPCP Targets SAP npm Packages: Mini Shai-Hulud Supply Chain Attack
HIGH
Supply Chain

TeamPCP Targets SAP npm Packages: Mini Shai-Hulud Supply Chain Attack

TeamPCP broadens supply chain attacks, compromising npm packages in SAP's cloud development ecosystem with the 'Mini Shai-Hulud' malicious code injection.

Runtime Rebel Intel
4 min read·May 1, 2026
SU
HIGH
Supply Chain

Official SAP npm Packages Compromised in TeamPCP Supply Chain Attack

Attackers compromised official SAP npm packages to exfiltrate developer credentials and tokens. Learn how to detect and remediate this supply chain threat.

Runtime Rebel Intel
3 min read·Apr 30, 2026
AI-Generated npm Supply Chain Attack: DPRK Exploits Claude Opus
CRITICAL
Supply Chain

AI-Generated npm Supply Chain Attack: DPRK Exploits Claude Opus

North Korean actors leverage LLMs like Claude Opus to insert malicious npm packages into developer workflows, leading to RCE and data theft via @validate-sdk/v2.

Runtime Rebel Intel
3 min read·Apr 29, 2026
SAP npm Packages Compromised by “Mini Shai-Hulud” Malware
HIGH
Supply Chain

SAP npm Packages Compromised by “Mini Shai-Hulud” Malware

The Mini Shai-Hulud campaign targets SAP cloud application developers with credential-stealing npm packages. Learn how to detect and mitigate this threat.

Runtime Rebel Intel
4 min read·Apr 29, 2026
SU
HIGH
Supply Chain

TeamPCP Supply Chain: Checkmarx KICS, Bitwarden CLI, xinference PyPI Attacks

TeamPCP resumes supply chain attacks with new compromises targeting Checkmarx KICS, Bitwarden CLI, and xinference PyPI. UNC6780 credential theft campaign continues.

Runtime Rebel Intel
5 min read·Apr 27, 2026
SU
HIGH
Supply Chain

Bitwarden NPM Supply Chain Attack: Analyzing the TeamPCP Campaign

A malicious npm package impersonating Bitwarden was discovered exfiltrating sensitive data via the Shai-Hulud worm in a recent supply chain attack.

Runtime Rebel Intel
3 min read·Apr 24, 2026
SU
HIGH
Supply Chain

Supply Chain Attack: Bitwarden CLI npm Package Compromised

Analysis of the Bitwarden CLI npm package compromise (version 2023.12.0) leading to developer credential theft and supply chain risk. Includes mitigation.

Runtime Rebel Intel
5 min read·Apr 23, 2026
Bitwarden CLI Supply Chain Attack: Malicious NPM Package Identified
CRITICAL
Supply Chain

Bitwarden CLI Supply Chain Attack: Malicious NPM Package Identified

Researchers have discovered a malicious payload in version 2026.4.0 of the Bitwarden CLI, targeting sensitive vault credentials in build environments.

Runtime Rebel Intel
3 min read·Apr 23, 2026
CanisterSprawl Worm: npm Package Supply Chain Hijack & Token Theft
HIGH
Supply Chain

CanisterSprawl Worm: npm Package Supply Chain Hijack & Token Theft

New CanisterSprawl worm compromises npm packages, propagates by stealing developer tokens via an ICP canister. Threatens software supply chain integrity.

Runtime Rebel Intel
4 min read·Apr 22, 2026
SU
HIGH
Supply Chain

Axios npm Supply Chain Attack: Malicious Payloads and Mitigation

Axios npm versions 1.14.1 and 0.30.4 compromised via a malicious dependency injecting remote access trojans. Learn how to detect and remediate this threat.

Runtime Rebel Intel
3 min read·Apr 21, 2026