Skip to main content
← All Articles

Tag

#npm

52 articles

Advertisement

npm Malware @openclaw-ai/openclawai: macOS Credential Theft Alert
HIGH
Supply Chain

npm Malware @openclaw-ai/openclawai: macOS Credential Theft Alert

Security alert for @openclaw-ai/openclawai, a malicious npm package targeting macOS users to deploy remote access trojans and steal sensitive credentials.

Runtime Rebel Intel
4 min read·Mar 9, 2026
North Korean Malicious npm Packages: Detecting Contagious Interview
HIGH
Supply Chain

North Korean Malicious npm Packages: Detecting Contagious Interview

North Korean actors published 26 malicious npm packages using Pastebin as a C2 dead drop resolver in a new Contagious Interview campaign iteration.

Runtime Rebel Intel
3 min read·Mar 2, 2026
SANDWORM_MODE: Malicious npm Cluster Automates Secret Harvesting and Crypto Theft
HIGH
Supply Chain

SANDWORM_MODE: Malicious npm Cluster Automates Secret Harvesting and Crypto Theft

Security researchers have identified a coordinated campaign involving 19 malicious npm packages designed to exfiltrate CI/CD secrets, API tokens, and private cryptocurrency keys.

Runtime Rebel Intel
2 min read·Feb 23, 2026
SU
HIGH
Supply Chain

Malicious npm Package Targets React Developers with Backdoored Polyfill

A typosquatted npm package mimicking a popular React utility has been downloaded over 47,000 times before removal. The package contained an obfuscated backdoor capable of exfiltrating environment variables and SSH keys.

Jordan Kim
2 min read·Jan 25, 2024