Skip to main content
← All Articles

Tag

#NPM

75 articles

Advertisement

TeamPCP Targets SAP npm Packages: Mini Shai-Hulud Supply Chain Attack
HIGH
Supply Chain

TeamPCP Targets SAP npm Packages: Mini Shai-Hulud Supply Chain Attack

TeamPCP broadens supply chain attacks, compromising npm packages in SAP's cloud development ecosystem with the 'Mini Shai-Hulud' malicious code injection.

Runtime Rebel Intel
4 min read · May 1, 2026
HIGH
Supply Chain

Official SAP npm Packages Compromised in TeamPCP Supply Chain Attack

Attackers compromised official SAP npm packages to exfiltrate developer credentials and tokens. Learn how to detect and remediate this supply chain threat.

Runtime Rebel Intel
4 min read · Apr 30, 2026
AI-Generated npm Supply Chain Attack: DPRK Exploits Claude Opus
HIGH
Supply Chain

AI-Generated npm Supply Chain Attack: DPRK Exploits Claude Opus

North Korean actors leverage LLMs like Claude Opus to insert malicious npm packages into developer workflows, leading to RCE and data theft via @validate-sdk/v2.

Runtime Rebel Intel
4 min read · Apr 29, 2026
SAP npm Packages Compromised by “Mini Shai-Hulud” Malware
HIGH
Supply Chain

SAP npm Packages Compromised by “Mini Shai-Hulud” Malware

The Mini Shai-Hulud campaign targets SAP cloud application developers with credential-stealing npm packages. Learn how to detect and mitigate this threat.

Runtime Rebel Intel
4 min read · Apr 29, 2026
HIGH
Supply Chain

TeamPCP Supply Chain: Checkmarx KICS, Bitwarden CLI, xinference PyPI Attacks

TeamPCP resumes supply chain attacks with new compromises targeting Checkmarx KICS, Bitwarden CLI, and xinference PyPI. UNC6780 credential theft campaign continues.

Runtime Rebel Intel
5 min read · Apr 27, 2026
HIGH
Supply Chain

Bitwarden NPM Supply Chain Attack: Analyzing the TeamPCP Campaign

A malicious npm package impersonating Bitwarden was discovered exfiltrating sensitive data via the Shai-Hulud worm in a recent supply chain attack.

Runtime Rebel Intel
4 min read · Apr 24, 2026

Advertisement

HIGH
Supply Chain

Supply Chain Attack: Bitwarden CLI npm Package Compromised

Analysis of the Bitwarden CLI npm package compromise (version 2023.12.0) leading to developer credential theft and supply chain risk. Includes mitigation.

Runtime Rebel Intel
5 min read · Apr 23, 2026
CanisterSprawl Worm: npm Package Supply Chain Hijack & Token Theft
HIGH
Supply Chain

CanisterSprawl Worm: npm Package Supply Chain Hijack & Token Theft

New CanisterSprawl worm compromises npm packages, propagates by stealing developer tokens via an ICP canister. Threatens software supply chain integrity.

Runtime Rebel Intel
4 min read · Apr 22, 2026
HIGH
Supply Chain

Axios npm Supply Chain Attack: Malicious Payloads and Mitigation

Axios npm versions 1.14.1 and 0.30.4 compromised via a malicious dependency injecting remote access trojans. Learn how to detect and remediate this threat.

Runtime Rebel Intel
4 min read · Apr 21, 2026
North Korean Hackers Distribute 1,700 Malicious Packages via npm and PyPI
HIGH
Supply Chain

North Korean Hackers Distribute 1,700 Malicious Packages via npm and PyPI

North Korean threat actors expand the Contagious Interview campaign, deploying 1,700 malicious packages across npm, PyPI, Go, and Rust ecosystems.

Runtime Rebel Intel
3 min read · Apr 8, 2026
Axios Attack: Industrialized Social Engineering on NPM Maintainers
HIGH
Supply Chain

Axios Attack: Industrialized Social Engineering on NPM Maintainers

An analysis of the Axios NPM package attack reveals advanced, scaled social engineering campaigns targeting open-source maintainers, elevating supply chain risk.

Runtime Rebel Intel
4 min read · Apr 7, 2026
HIGH
Supply Chain

North Korean Social Engineering Targets Node.js Maintainers

North Korean threat actors use social engineering and malicious npm packages to target high-profile Node.js maintainers in a sophisticated supply chain campaign.

Runtime Rebel Intel
3 min read · Apr 6, 2026
HIGH
Supply Chain

Guardarian Users Targeted via 36 Malicious Strapi npm Packages

Analysis of a supply chain attack involving 36 malicious npm packages posing as Strapi plugins to target Guardarian users and harvest sensitive credentials.

Runtime Rebel Intel
4 min read · Apr 6, 2026
HIGH
Supply Chain

Axios npm Hijack Attempt: Detecting Social Engineering Tactics

North Korean threat actors targeted an Axios maintainer with a fake Microsoft Teams fix, highlighting critical risks to open-source supply chains.

Runtime Rebel Intel
3 min read · Apr 5, 2026
UNC1069 Social Engineering Leads to Axios npm Supply Chain Compromise
HIGH
Supply Chain

UNC1069 Social Engineering Leads to Axios npm Supply Chain Compromise

Runtime Rebel details how North Korean threat actor UNC1069 leveraged targeted social engineering against an Axios npm package maintainer, leading to a critical supply…

Runtime Rebel Intel
4 min read · Apr 3, 2026
HIGH
Supply Chain

Axios NPM Supply Chain Attack Bypasses GitHub Actions CI/CD

A sophisticated supply chain attack targeted the Axios NPM package, leveraging a compromised token to bypass GitHub Actions CI/CD and deploy malicious versions.

Runtime Rebel Intel
4 min read · Apr 1, 2026
Axios npm Supply Chain Attack Attributed to North Korea's UNC1069
HIGH
Supply Chain

Axios npm Supply Chain Attack Attributed to North Korea's UNC1069

Google Threat Intelligence attributes a major Axios npm supply chain attack to North Korean group UNC1069, emphasizing risks to developer environments.

Runtime Rebel Intel
4 min read · Apr 1, 2026
HIGH
Supply Chain

UNC1069 Leverages Axios NPM Supply Chain to Deploy WAVESHAPER.V2

North Korea-nexus UNC1069 compromised widely used Axios NPM package (v1.14.1, 0.30.4) by injecting plain-crypto-js to deploy WAVESHAPER.V2 backdoor across multiple OS.

Runtime Rebel Intel
8 min read · Apr 1, 2026
Axios NPM Compromise: Supply Chain Threat Analysis
HIGH
Supply Chain

Axios NPM Compromise: Supply Chain Threat Analysis

Analysis of the Axios NPM package compromise, a potential supply chain attack impacting JavaScript HTTP client library users, possibly by North Korean threat actors.

Runtime Rebel Intel
5 min read · Apr 1, 2026
MEDIUM
Supply Chain

Anthropic Claude Code Source Code Leaked via NPM Registry

Anthropic accidentally exposed proprietary source code for its Claude Code CLI tool on the public npm registry. Analyze the technical impact and risks.

Runtime Rebel Intel
3 min read · Apr 1, 2026
HIGH
Supply Chain

Axios npm Package Hijacked: Cross-Platform Malware Distribution

Analysis of the Axios npm package hijack distributing remote access trojans to Linux, Windows, and macOS systems. Learn to protect your software supply chain.

Runtime Rebel Intel
5 min read · Mar 31, 2026
npm Ghost Campaign: 7 Malicious Packages Steal Crypto Wallets
HIGH
Supply Chain

npm Ghost Campaign: 7 Malicious Packages Steal Crypto Wallets

ReversingLabs uncovers the Ghost campaign targeting developers with 7 malicious npm packages designed to exfiltrate cryptocurrency wallets and credentials.

Runtime Rebel Intel
3 min read · Mar 24, 2026
Trivy Supply Chain Attack Spreads CanisterWorm via 47 npm Packages
HIGH
Supply Chain

Trivy Supply Chain Attack Spreads CanisterWorm via 47 npm Packages

Attackers compromise 47 npm packages using CanisterWorm, a self-propagating threat leveraging ICP canisters following a major Trivy supply chain attack.

Runtime Rebel Intel
3 min read · Mar 21, 2026
npm Malware @openclaw-ai/openclawai: macOS Credential Theft Alert
HIGH
Supply Chain

npm Malware @openclaw-ai/openclawai: macOS Credential Theft Alert

Security alert for @openclaw-ai/openclawai, a malicious npm package targeting macOS users to deploy remote access trojans and steal sensitive credentials.

Runtime Rebel Intel
4 min read · Mar 9, 2026