<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #NPM</title><description>Cybersecurity articles tagged #NPM on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Hackers Abuse npm Mirrors to Host Phishing Redirects</title><link>https://runtimerebel.com/blog/hackers-abuse-npm-mirrors-to-host-phishing-redirects</link><guid isPermaLink="true">https://runtimerebel.com/blog/hackers-abuse-npm-mirrors-to-host-phishing-redirects</guid><description>Threat actors exploit npm and its mirroring platforms like UNPKG to host malicious HTML pages, impersonating Cloudflare CAPTCHAs for phishing redirects.</description><pubDate>Wed, 26 Aug 2026 08:31:38 GMT</pubDate><category>NPM</category><category>Phishing</category><category>Supply Chain Attack</category><category>UNPKG</category><category>Cloudflare Impersonation</category></item><item><title>Trojanized npm Packages Deliver AI-Powered RedC2 4.0 Linux Backdoor</title><link>https://runtimerebel.com/blog/trojanized-npm-packages-deliver-ai-powered-redc2-4-0-linux-backdoor</link><guid isPermaLink="true">https://runtimerebel.com/blog/trojanized-npm-packages-deliver-ai-powered-redc2-4-0-linux-backdoor</guid><description>Malicious npm packages deliver RedC2 4.0 Linux backdoor, featuring AI-assisted command and control for advanced post-exploitation.</description><pubDate>Sat, 22 Aug 2026 00:39:04 GMT</pubDate><category>NPM</category><category>Linux Backdoor</category><category>Supply Chain Attack</category><category>AI</category><category>RedC2</category></item><item><title>npm Supply Chain Attacks: Shai-Hulud, Miasma, and CI/CD Compromises</title><link>https://runtimerebel.com/blog/npm-supply-chain-attacks-shai-hulud-miasma-and-ci-cd-compromises</link><guid isPermaLink="true">https://runtimerebel.com/blog/npm-supply-chain-attacks-shai-hulud-miasma-and-ci-cd-compromises</guid><description>The npm ecosystem faces escalating supply chain attacks like Shai-Hulud and Miasma RAT, leading to credential theft and widespread package compromise.</description><pubDate>Sat, 08 Aug 2026 16:26:28 GMT</pubDate><category>NPM</category><category>Supply Chain Attack</category><category>Shai Hulud</category><category>TeamPCP</category><category>CI CD Security</category></item><item><title>Critical npm Supply Chain Attack Delivers Cross-Platform RAT/Infostealer</title><link>https://runtimerebel.com/blog/critical-npm-supply-chain-attack-delivers-cross-platform-rat-infostealer</link><guid isPermaLink="true">https://runtimerebel.com/blog/critical-npm-supply-chain-attack-delivers-cross-platform-rat-infostealer</guid><description>Critical npm supply chain attack involving nearly 800 malicious packages delivers WEL1DROPPER RAT and infostealer to Windows, macOS, and Linux users.</description><pubDate>Sat, 08 Aug 2026 00:54:29 GMT</pubDate><category>NPM</category><category>Supply Chain Attack</category><category>Infostealer</category><category>RAT</category><category>WEL1DROPPER</category></item><item><title>ChainDrop npm Worm: Self-Propagating Software Supply Chain Threat</title><link>https://runtimerebel.com/blog/chaindrop-npm-worm-self-propagating-software-supply-chain-threat</link><guid isPermaLink="true">https://runtimerebel.com/blog/chaindrop-npm-worm-self-propagating-software-supply-chain-threat</guid><description>Analyze the ChainDrop self-propagating npm worm infecting major packages, harvesting credentials from memory, and compromising CI/CD pipelines.</description><pubDate>Fri, 07 Aug 2026 02:13:34 GMT</pubDate><category>Supply Chain Attack</category><category>Malware</category><category>NPM</category><category>GitHub Actions</category><category>Credential Theft</category></item><item><title>Keyv npm Supply-Chain Attack: Worm Infection and Dead-Man Switch</title><link>https://runtimerebel.com/blog/keyv-npm-supply-chain-attack-worm-infection-and-dead-man-switch</link><guid isPermaLink="true">https://runtimerebel.com/blog/keyv-npm-supply-chain-attack-worm-infection-and-dead-man-switch</guid><description>Analyze the Keyv/cacheable npm supply-chain worm, its AI agent execution vectors, and why immediate credential revocation can trigger payloads.</description><pubDate>Thu, 06 Aug 2026 02:00:17 GMT</pubDate><category>Supply Chain Attack</category><category>NPM</category><category>Credential Theft</category><category>Zero-Day</category><category>Malware</category></item><item><title>ChainDrop npm Supply Chain Attack Steals Developer Credentials</title><link>https://runtimerebel.com/blog/chaindrop-npm-supply-chain-attack-steals-developer-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/chaindrop-npm-supply-chain-attack-steals-developer-credentials</guid><description>Massive ChainDrop npm supply chain attack compromises over 1,300 packages, stealing developer and cloud credentials through malicious preinstall scripts.</description><pubDate>Tue, 04 Aug 2026 17:30:58 GMT</pubDate><category>NPM</category><category>Supply Chain Attack</category><category>Infostealer</category><category>JavaScript</category><category>ChainDrop</category></item><item><title>Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Users</title><link>https://runtimerebel.com/blog/malicious-npm-packages-deliver-cross-platform-rat-to-alibaba-users</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-npm-packages-deliver-cross-platform-rat-to-alibaba-users</guid><description>Discover how 18 malicious npm packages target Alibaba developer tools with a cross-platform remote access trojan in a supply chain attack.</description><pubDate>Tue, 04 Aug 2026 01:27:44 GMT</pubDate><category>Supply Chain Attack</category><category>Malware</category><category>NPM</category><category>Remote Access Trojan</category></item><item><title>North Korean Hackers Exploit npm Supply Chain: Debug &amp; Chalk Under Attack</title><link>https://runtimerebel.com/blog/north-korean-hackers-exploit-npm-supply-chain-debug-chalk-under-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/north-korean-hackers-exploit-npm-supply-chain-debug-chalk-under-attack</guid><description>Amazon links North Korean hackers to supply chain attacks on popular npm packages Debug and Chalk, highlighting nation-state threat to open-source ecosystems.</description><pubDate>Thu, 30 Jul 2026 21:12:11 GMT</pubDate><category>North Korean Hackers</category><category>NPM</category><category>Supply Chain Attack</category><category>Debug</category><category>Chalk</category><category>Software Supply Chain Security</category></item><item><title>Compromised Joyfill npm Packages Deliver DEV#POPPER RAT</title><link>https://runtimerebel.com/blog/compromised-joyfill-npm-packages-deliver-dev-popper-rat</link><guid isPermaLink="true">https://runtimerebel.com/blog/compromised-joyfill-npm-packages-deliver-dev-popper-rat</guid><description>Beta versions of @joyfill/layouts and @joyfill/components npm packages compromised to deliver a DEV#POPPER RAT upon import. Node.js users at risk.</description><pubDate>Wed, 29 Jul 2026 06:32:18 GMT</pubDate><category>Joyfill</category><category>NPM</category><category>Supply Chain Attack</category><category>RAT</category><category>DEV POPPER</category><category>Node Js</category></item><item><title>Malicious Vite npm Packages Deliver RAT via Blockchain C2</title><link>https://runtimerebel.com/blog/malicious-vite-npm-packages-deliver-rat-via-blockchain-c2</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-vite-npm-packages-deliver-rat-via-blockchain-c2</guid><description>Seven malicious npm packages target Vite frontend projects. Dubbed ViteVenom, this software supply chain attack uses a four-tier blockchain C2 to deploy a RAT.</description><pubDate>Fri, 17 Jul 2026 20:57:56 GMT</pubDate><category>ViteVenom</category><category>ChainVeil</category><category>NPM</category><category>Vite</category><category>Software Supply Chain Attack</category><category>RAT</category><category>Blockchain C2</category></item><item><title>AsyncAPI npm packages infected with credential-stealing malware</title><link>https://runtimerebel.com/blog/asyncapi-npm-packages-infected-with-credential-stealing-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/asyncapi-npm-packages-infected-with-credential-stealing-malware</guid><description>Five malicious versions of AsyncAPI npm packages deployed a credential-stealing remote access trojan via a supply chain attack. Learn detection and mitigation.</description><pubDate>Wed, 15 Jul 2026 17:20:00 GMT</pubDate><category>NPM</category><category>Asyncapi</category><category>Supply Chain Attack</category><category>Credential Stealing</category><category>Malware</category><category>Trojan</category></item><item><title>Jscrambler NPM Packages Poisoned in Supply Chain Attack</title><link>https://runtimerebel.com/blog/jscrambler-npm-packages-poisoned-in-supply-chain-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/jscrambler-npm-packages-poisoned-in-supply-chain-attack</guid><description>Attackers poisoned official Jscrambler NPM packages to distribute cross-platform credential stealers. Learn the impact and how to remediate the threat.</description><pubDate>Tue, 14 Jul 2026 10:01:24 GMT</pubDate><category>Jscrambler</category><category>NPM</category><category>Supply Chain Attack</category><category>Malware</category><category>Credential Stealer</category></item><item><title>Jscrambler npm Package Backdoored with Infostealer Malware</title><link>https://runtimerebel.com/blog/jscrambler-npm-package-backdoored-with-infostealer-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/jscrambler-npm-package-backdoored-with-infostealer-malware</guid><description>A malicious version of the Jscrambler npm package, 5.0.0-beta-1, was backdoored with infostealer malware, affecting 1,500 downloads. Immediate action needed.</description><pubDate>Mon, 13 Jul 2026 20:59:06 GMT</pubDate><category>Jscrambler</category><category>NPM</category><category>Supply Chain Attack</category><category>Infostealer</category><category>Malware</category><category>Node Js</category></item><item><title>jscrambler 8.14.0 Compromised: Rust Infostealer Supply Chain Attack</title><link>https://runtimerebel.com/blog/jscrambler-8-14-0-compromised-rust-infostealer-supply-chain-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/jscrambler-8-14-0-compromised-rust-infostealer-supply-chain-attack</guid><description>The jscrambler 8.14.0 npm release was compromised with a malicious preinstall hook dropping a cross-platform Rust infostealer. Mitigate the threat now.</description><pubDate>Sat, 11 Jul 2026 20:50:45 GMT</pubDate><category>Jscrambler</category><category>NPM</category><category>Supply Chain Attack</category><category>Rust Malware</category><category>Infostealer</category></item><item><title>Injective Labs npm Package Compromise Steals Crypto Keys</title><link>https://runtimerebel.com/blog/injective-labs-npm-package-compromise-steals-crypto-keys</link><guid isPermaLink="true">https://runtimerebel.com/blog/injective-labs-npm-package-compromise-steals-crypto-keys</guid><description>Critical supply chain attack compromises Injective Labs SDK on GitHub, distributing malicious npm package `@injectivelabs/sdk-ts@1.20.21` to steal crypto wallet keys.</description><pubDate>Fri, 10 Jul 2026 17:48:42 GMT</pubDate><category>Injective Labs</category><category>NPM</category><category>Supply Chain Attack</category><category>Cryptocurrency</category><category>Wallet Theft</category><category>Malicious Package</category><category>SDK</category></item><item><title>Injective SDK npm Compromise: Crypto Wallet Stealer Detected</title><link>https://runtimerebel.com/blog/injective-sdk-npm-compromise-crypto-wallet-stealer-detected</link><guid isPermaLink="true">https://runtimerebel.com/blog/injective-sdk-npm-compromise-crypto-wallet-stealer-detected</guid><description>A malicious version of the Injective SDK (injective-js) on npm was published via a GitHub compromise, deploying a crypto wallet stealer. Developers are at risk.</description><pubDate>Fri, 10 Jul 2026 03:32:02 GMT</pubDate><category>Injective SDK</category><category>NPM</category><category>Cryptocurrency</category><category>Wallet Stealer</category><category>Supply Chain Attack</category><category>Malware</category><category>Injective Js</category></item><item><title>npm 12 Enhances Supply Chain Security by Disabling Install Scripts</title><link>https://runtimerebel.com/blog/npm-12-enhances-supply-chain-security-by-disabling-install-scripts</link><guid isPermaLink="true">https://runtimerebel.com/blog/npm-12-enhances-supply-chain-security-by-disabling-install-scripts</guid><description>npm version 12 introduces critical security defaults, disabling install scripts and deprecating GATs, significantly mitigating JavaScript supply chain risks.</description><pubDate>Thu, 09 Jul 2026 17:57:40 GMT</pubDate><category>NPM</category><category>Supply Chain Security</category><category>Install Scripts</category><category>Security Defaults</category><category>GATs</category><category>2FA</category><category>JavaScript Packages</category></item><item><title>Fake Paysafe/Skrill SDKs on npm &amp; PyPI Steal Credentials</title><link>https://runtimerebel.com/blog/fake-paysafe-skrill-sdks-on-npm-pypi-steal-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/fake-paysafe-skrill-sdks-on-npm-pypi-steal-credentials</guid><description>Malicious packages impersonating Paysafe and Skrill SDKs on npm and PyPI platforms are stealing credentials from developers and users. Threat intelligence analysis.</description><pubDate>Wed, 08 Jul 2026 21:35:17 GMT</pubDate><category>NPM</category><category>PyPI</category><category>Supply Chain Attack</category><category>Credential Theft</category><category>Paysafe</category><category>Skrill</category><category>Neteller</category><category>Malware</category></item><item><title>PolinRider: North Korean Hackers Push 108 Malicious Packages</title><link>https://runtimerebel.com/blog/polinrider-north-korean-hackers-push-108-malicious-packages</link><guid isPermaLink="true">https://runtimerebel.com/blog/polinrider-north-korean-hackers-push-108-malicious-packages</guid><description>Analysis of the PolinRider campaign where North Korean actors published 108 malicious packages and extensions across npm, Go, and Chrome ecosystems.</description><pubDate>Sat, 04 Jul 2026 13:37:02 GMT</pubDate><category>PolinRider</category><category>Lazarus Group</category><category>NPM</category><category>Chrome Web Store</category><category>Supply Chain Attack</category><category>North Korea</category></item><item><title>N. Korea-Linked npm Packages Mimic Rollup Polyfills for Data Theft</title><link>https://runtimerebel.com/blog/n-korea-linked-npm-packages-mimic-rollup-polyfills-for-data-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/n-korea-linked-npm-packages-mimic-rollup-polyfills-for-data-theft</guid><description>North Korea-linked actors use malicious npm packages (&apos;rollup-packages-polyfill-core&apos;, &apos;rollup-runtime-polyfill-core&apos;) to steal developer secrets, mimicking Rollup…</description><pubDate>Fri, 03 Jul 2026 17:27:44 GMT</pubDate><category>NPM</category><category>Rollup</category><category>Supply Chain Attack</category><category>North Korea Linked</category><category>Developer Secrets</category><category>Malicious Packages</category></item><item><title>Malicious npm Packages Impersonate PostCSS to Deliver Windows RAT</title><link>https://runtimerebel.com/blog/malicious-npm-packages-impersonate-postcss-to-deliver-windows-rat</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-npm-packages-impersonate-postcss-to-deliver-windows-rat</guid><description>Security researchers uncover malicious npm packages such as postcss-minify-selector-parser delivering Windows RATs via supply chain attacks. Audit your builds.</description><pubDate>Tue, 23 Jun 2026 13:10:31 GMT</pubDate><category>NPM</category><category>PostCSS</category><category>Typosquatting</category><category>RAT</category><category>JavaScript</category></item><item><title>North Korean Sapphire Sleet Compromises 140+ Mastra AI npm Packages</title><link>https://runtimerebel.com/blog/north-korean-sapphire-sleet-compromises-140-mastra-ai-npm-packages</link><guid isPermaLink="true">https://runtimerebel.com/blog/north-korean-sapphire-sleet-compromises-140-mastra-ai-npm-packages</guid><description>Microsoft attributes the Mastra AI supply chain attack to Sapphire Sleet (BlueNoroff), involving 140+ malicious npm packages targeting AI developers.</description><pubDate>Sat, 20 Jun 2026 16:38:13 GMT</pubDate><category>Sapphire Sleet</category><category>BlueNoroff</category><category>Mastra AI</category><category>NPM</category><category>Supply Chain Attack</category><category>Lazarus Group</category></item><item><title>NastyC2 npm Packages, AI Abuse &amp; macOS Threats Identified</title><link>https://runtimerebel.com/blog/nastyc2-npm-packages-ai-abuse-macos-threats-identified</link><guid isPermaLink="true">https://runtimerebel.com/blog/nastyc2-npm-packages-ai-abuse-macos-threats-identified</guid><description>Analysis of NastyC2 npm supply chain attacks, Claude chat abuse for malware, memory-resident macOS threats, and device-code phishing.</description><pubDate>Thu, 18 Jun 2026 17:09:21 GMT</pubDate><category>NastyC2</category><category>NPM</category><category>Supply Chain Attack</category><category>Claude</category><category>AI Abuse</category><category>macOS Malware</category><category>Phishing</category><category>Cloud Security</category><category>Browser Add on</category></item><item><title>npm 12 Security: Default Script Execution Changes to Mitigate Supply Chain Attacks</title><link>https://runtimerebel.com/blog/npm-12-security-default-script-execution-changes-to-mitigate-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/npm-12-security-default-script-execution-changes-to-mitigate-supply-chain-attacks</guid><description>npm 12 introduces a critical change: &apos;npm install&apos; will no longer run dependency scripts by default, significantly reducing software supply chain risks.</description><pubDate>Sat, 13 Jun 2026 16:36:33 GMT</pubDate><category>NPM</category><category>Supply Chain Attack</category><category>Node Js</category><category>Dependency Scripts</category><category>Software Security</category><category>Package Manager</category></item><item><title>GitHub to Disable npm Install Scripts by Default in Version 12</title><link>https://runtimerebel.com/blog/github-to-disable-npm-install-scripts-by-default-in-version-12</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-to-disable-npm-install-scripts-by-default-in-version-12</guid><description>GitHub announces breaking changes for npm v12, disabling install scripts by default to prevent malicious code execution and enhance supply chain security.</description><pubDate>Thu, 11 Jun 2026 09:37:20 GMT</pubDate><category>NPM</category><category>GitHub</category><category>Npm V12</category><category>Supply Chain Security</category><category>Malware Prevention</category></item><item><title>npm Supply Chain Attack: IronWorm and Miasma Malware Analysis</title><link>https://runtimerebel.com/blog/npm-supply-chain-attack-ironworm-and-miasma-malware-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/npm-supply-chain-attack-ironworm-and-miasma-malware-analysis</guid><description>Threat actors target npm developers with the IronWorm info stealer and Miasma worm, utilizing eBPF rootkits to exfiltrate secrets and ensure persistence.</description><pubDate>Fri, 05 Jun 2026 20:40:47 GMT</pubDate><category>NPM</category><category>IronWorm</category><category>Miasma</category><category>Supply Chain Attack</category><category>Malware</category><category>Rust</category><category>eBPF</category></item><item><title>IronWorm: Rust-Written Malware Hits npm Supply Chain Developers</title><link>https://runtimerebel.com/blog/ironworm-rust-written-malware-hits-npm-supply-chain-developers</link><guid isPermaLink="true">https://runtimerebel.com/blog/ironworm-rust-written-malware-hits-npm-supply-chain-developers</guid><description>Analysis of the Rust-written IronWorm malware targeting npm supply chain developers.</description><pubDate>Fri, 05 Jun 2026 01:01:31 GMT</pubDate><category>IronWorm</category><category>Rust</category><category>NPM</category><category>Supply Chain Attack</category><category>Credential Theft</category><category>Developer Security</category></item><item><title>IronWorm Malware: 36 npm Packages Identified in Supply Chain Attack</title><link>https://runtimerebel.com/blog/ironworm-malware-36-npm-packages-identified-in-supply-chain-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/ironworm-malware-36-npm-packages-identified-in-supply-chain-attack</guid><description>Security researchers discover a campaign delivering IronWorm infostealer malware via 36 malicious npm packages using preinstall script execution hooks.</description><pubDate>Thu, 04 Jun 2026 17:09:30 GMT</pubDate><category>NPM</category><category>IronWorm</category><category>Infostealer</category><category>Supply Chain Attack</category><category>JavaScript</category></item><item><title>Red Hat npm Supply Chain Compromise: Miasma Steals Dev Credentials</title><link>https://runtimerebel.com/blog/red-hat-npm-supply-chain-compromise-miasma-steals-dev-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/red-hat-npm-supply-chain-compromise-miasma-steals-dev-credentials</guid><description>Over 30 Red Hat npm packages under @redhat-cloud-services were compromised in a supply chain attack distributing Miasma malware to steal developer credentials.</description><pubDate>Tue, 02 Jun 2026 01:03:30 GMT</pubDate><category>Red Hat</category><category>NPM</category><category>Supply Chain Attack</category><category>Miasma</category><category>Shai Hulud</category><category>Developer Credentials</category><category>Credential Theft</category></item><item><title>Miasma Supply Chain Attack: Defending Red Hat npm Environments</title><link>https://runtimerebel.com/blog/miasma-supply-chain-attack-defending-red-hat-npm-environments</link><guid isPermaLink="true">https://runtimerebel.com/blog/miasma-supply-chain-attack-defending-red-hat-npm-environments</guid><description>Analysis of the Miasma supply chain attack targeting Red Hat npm packages with credential-stealing worms. Technical details and mitigation guide for SOC teams.</description><pubDate>Mon, 01 Jun 2026 21:14:46 GMT</pubDate><category>Red Hat</category><category>NPM</category><category>Miasma</category><category>Supply Chain Attack</category><category>Credential Theft</category><category>Mini Shai Hulud</category></item><item><title>Malicious npm Package Targets Claude AI User Data — Technical Analysis</title><link>https://runtimerebel.com/blog/malicious-npm-package-targets-claude-ai-user-data-technical-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-npm-package-targets-claude-ai-user-data-technical-analysis</guid><description>Researchers discover mouse5212-super-formatter, a malicious npm package designed to exfiltrate sensitive files from Claude AI user directories.</description><pubDate>Wed, 27 May 2026 17:12:05 GMT</pubDate><category>NPM</category><category>Claude AI</category><category>Supply Chain Attack</category><category>Data Exfiltration</category><category>Anthropic</category></item><item><title>Shai-Hulud Campaign: TeamPCP Targets Open-Source Supply Chain</title><link>https://runtimerebel.com/blog/shai-hulud-campaign-teampcp-targets-open-source-supply-chain</link><guid isPermaLink="true">https://runtimerebel.com/blog/shai-hulud-campaign-teampcp-targets-open-source-supply-chain</guid><description>Analysis of the Shai-Hulud campaign by TeamPCP, detailing their open-source supply chain attacks, TTPs, and critical mitigation strategies.</description><pubDate>Tue, 26 May 2026 20:47:57 GMT</pubDate><category>TeamPCP</category><category>Shai Hulud</category><category>Supply Chain Attack</category><category>Open Source Security</category><category>NPM</category><category>PyPI</category><category>Malicious Packages</category></item><item><title>TeamPCP Supply Chain Attack Targets Microsoft SDKs and GitHub</title><link>https://runtimerebel.com/blog/teampcp-supply-chain-attack-targets-microsoft-sdks-and-github</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-supply-chain-attack-targets-microsoft-sdks-and-github</guid><description>TeamPCP expands its supply chain campaign to trojanize official Microsoft Python SDKs and infiltrate GitHub, requiring immediate dependency audits.</description><pubDate>Mon, 25 May 2026 16:52:00 GMT</pubDate><category>TeamPCP</category><category>Supply Chain Attack</category><category>Python SDK</category><category>GitHub</category><category>PyPI</category><category>NPM</category></item><item><title>TrapDoor Campaign: Detecting Cross-Ecosystem Supply Chain Attacks</title><link>https://runtimerebel.com/blog/trapdoor-campaign-detecting-cross-ecosystem-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/trapdoor-campaign-detecting-cross-ecosystem-supply-chain-attacks</guid><description>The TrapDoor campaign targets npm, PyPI, and Crates.io with over 384 malicious versions designed to exfiltrate developer credentials and sensitive data.</description><pubDate>Mon, 25 May 2026 09:28:16 GMT</pubDate><category>Trapdoor</category><category>NPM</category><category>PyPI</category><category>Crates Io</category><category>Credential Theft</category><category>Software Supply Chain</category></item><item><title>npm Staged Publishing: New 2FA Controls Prevent Supply Chain Attacks</title><link>https://runtimerebel.com/blog/npm-staged-publishing-new-2fa-controls-prevent-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/npm-staged-publishing-new-2fa-controls-prevent-supply-chain-attacks</guid><description>GitHub introduces staged publishing for npm, requiring manual 2FA approval for package releases to mitigate malicious automated updates and account takeovers.</description><pubDate>Sat, 23 May 2026 20:21:54 GMT</pubDate><category>NPM</category><category>GitHub</category><category>Supply Chain Security</category><category>Two Factor Authentication</category><category>Staged Publishing</category><category>Application Security</category></item><item><title>Analysis of Cross-Platform NPM Stealer Using Discord Webhooks</title><link>https://runtimerebel.com/blog/analysis-of-cross-platform-npm-stealer-using-discord-webhooks</link><guid isPermaLink="true">https://runtimerebel.com/blog/analysis-of-cross-platform-npm-stealer-using-discord-webhooks</guid><description>Technical teardown of an obfuscated Node.js infostealer targeting Discord tokens, crypto wallets, and browser credentials via cross-platform scripts.</description><pubDate>Fri, 22 May 2026 09:17:57 GMT</pubDate><category>NPM</category><category>Node Js</category><category>Infostealer</category><category>Discord Webhook</category><category>Obfuscation</category></item><item><title>GitHub Repository Breach Linked to TanStack Supply Chain Attack</title><link>https://runtimerebel.com/blog/github-repository-breach-linked-to-tanstack-supply-chain-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-repository-breach-linked-to-tanstack-supply-chain-attack</guid><description>GitHub confirms the breach of 3,800 internal repositories via a compromised VS Code extension linked to the TanStack npm supply chain attack.</description><pubDate>Thu, 21 May 2026 09:15:44 GMT</pubDate><category>GitHub</category><category>TanStack</category><category>NPM</category><category>Supply Chain Attack</category><category>VS Code</category></item><item><title>Grafana Breach After TanStack Attack: Token Rotation Failure</title><link>https://runtimerebel.com/blog/grafana-breach-after-tanstack-attack-token-rotation-failure</link><guid isPermaLink="true">https://runtimerebel.com/blog/grafana-breach-after-tanstack-attack-token-rotation-failure</guid><description>Grafana suffered a data breach due to a GitHub workflow token not rotated after the TanStack npm supply-chain attack, impacting user data. Learn the details.</description><pubDate>Wed, 20 May 2026 17:12:03 GMT</pubDate><category>Grafana</category><category>TanStack</category><category>NPM</category><category>Supply Chain Attack</category><category>GitHub Actions</category><category>Token Rotation</category><category>Data Breach</category></item><item><title>320+ @antv NPM Packages Compromised in Mini Shai-Hulud Attack</title><link>https://runtimerebel.com/blog/320-antv-npm-packages-compromised-in-mini-shai-hulud-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/320-antv-npm-packages-compromised-in-mini-shai-hulud-attack</guid><description>A maintainer account compromise has led to a major supply chain attack against Alibaba’s @antv NPM namespace, impacting over 320 visualization packages.</description><pubDate>Wed, 20 May 2026 13:06:33 GMT</pubDate><category>NPM</category><category>Mini Shai Hulud</category><category>Antv</category><category>Supply Chain Security</category><category>JavaScript</category></item><item><title>TeamPCP Jenkins Plugin Compromise and Mini Shai-Hulud Worm Analysis</title><link>https://runtimerebel.com/blog/teampcp-jenkins-plugin-compromise-and-mini-shai-hulud-worm-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-jenkins-plugin-compromise-and-mini-shai-hulud-worm-analysis</guid><description>TeamPCP escalates its supply chain campaign with a confirmed Jenkins plugin compromise and a self-spreading worm targeting the npm and PyPI ecosystems.</description><pubDate>Mon, 18 May 2026 20:38:04 GMT</pubDate><category>TeamPCP</category><category>Jenkins</category><category>NPM</category><category>PyPI</category><category>Mini Shai Hulud</category><category>Supply Chain Attack</category></item><item><title>Shai-Hulud Infostealer Surfaces in Malicious npm Package Campaign</title><link>https://runtimerebel.com/blog/shai-hulud-infostealer-surfaces-in-malicious-npm-package-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/shai-hulud-infostealer-surfaces-in-malicious-npm-package-campaign</guid><description>Leaked Shai-Hulud malware is targeting Node.js developers via malicious npm packages, exfiltrating sensitive data and credentials to Telegram-based C2.</description><pubDate>Mon, 18 May 2026 20:37:20 GMT</pubDate><category>NPM</category><category>Shai Hulud</category><category>Infostealer</category><category>Supply Chain Attack</category><category>Malicious Packages</category></item><item><title>Microsoft Exchange Zero-Day and npm Supply Chain Worm Under Active Use</title><link>https://runtimerebel.com/blog/microsoft-exchange-zero-day-and-npm-supply-chain-worm-under-active-use</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-exchange-zero-day-and-npm-supply-chain-worm-under-active-use</guid><description>Critical security briefing on the active exploitation of an Exchange Server zero-day, npm supply chain worms, and Cisco network control vulnerabilities.</description><pubDate>Mon, 18 May 2026 17:03:13 GMT</pubDate><category>Exchange Server</category><category>NPM</category><category>Supply Chain Attack</category><category>Cisco</category><category>Zero-Day</category></item><item><title>Developer Workstations: The New Front in Software Supply Chain Attacks</title><link>https://runtimerebel.com/blog/developer-workstations-the-new-front-in-software-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/developer-workstations-the-new-front-in-software-supply-chain-attacks</guid><description>A surge in attacks targeting npm, PyPI, and Docker Hub highlights a shift toward stealing developer credentials and API keys from workstations and CI/CD pipelines.</description><pubDate>Mon, 18 May 2026 13:23:15 GMT</pubDate><category>NPM</category><category>PyPI</category><category>Docker Hub</category><category>CI CD Security</category><category>Credential Theft</category><category>Developer Security</category></item><item><title>OpenAI Breach: TanStack Supply Chain Attack Impacts Employee Devices</title><link>https://runtimerebel.com/blog/openai-breach-tanstack-supply-chain-attack-impacts-employee-devices</link><guid isPermaLink="true">https://runtimerebel.com/blog/openai-breach-tanstack-supply-chain-attack-impacts-employee-devices</guid><description>OpenAI confirms two employee devices compromised in a TanStack supply chain attack affecting npm and PyPI packages, prompting certificate rotation.</description><pubDate>Thu, 14 May 2026 20:37:10 GMT</pubDate><category>OpenAI</category><category>TanStack</category><category>Supply Chain Attack</category><category>NPM</category><category>PyPI</category><category>Certificate Rotation</category></item><item><title>Malicious node-ipc Versions Compromise Developer Secrets via Supply Chain</title><link>https://runtimerebel.com/blog/malicious-node-ipc-versions-compromise-developer-secrets-via-supply-chain</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-node-ipc-versions-compromise-developer-secrets-via-supply-chain</guid><description>Three versions of the node-ipc npm package (9.1.6, 9.2.3, 12.0.1) contain stealer/backdoor functionality targeting developer secrets. Urgent update advised.</description><pubDate>Thu, 14 May 2026 20:36:23 GMT</pubDate><category>Node Ipc</category><category>NPM</category><category>Supply Chain Attack</category><category>Developer Secrets</category><category>Backdoor</category><category>Stealer</category></item><item><title>Shai-Hulud Supply Chain Attack: Malicious npm and Mistral Packages</title><link>https://runtimerebel.com/blog/shai-hulud-supply-chain-attack-malicious-npm-and-mistral-packages</link><guid isPermaLink="true">https://runtimerebel.com/blog/shai-hulud-supply-chain-attack-malicious-npm-and-mistral-packages</guid><description>The Shai-Hulud campaign targets developers with over 300 signed npm and PyPI packages impersonating TanStack and Mistral to steal sensitive credentials.</description><pubDate>Tue, 12 May 2026 12:48:53 GMT</pubDate><category>Shai Hulud</category><category>NPM</category><category>PyPI</category><category>Supply Chain Attack</category><category>Mistral AI</category><category>TanStack</category><category>Credential Stealer</category></item><item><title>Mini Shai-Hulud Worm Compromises TanStack and Mistral AI Packages</title><link>https://runtimerebel.com/blog/mini-shai-hulud-worm-compromises-tanstack-and-mistral-ai-packages</link><guid isPermaLink="true">https://runtimerebel.com/blog/mini-shai-hulud-worm-compromises-tanstack-and-mistral-ai-packages</guid><description>TeamPCP actor compromises major npm and PyPI packages including TanStack and Mistral AI via the Mini Shai-Hulud worm, deploying profiling malware.</description><pubDate>Tue, 12 May 2026 09:04:37 GMT</pubDate><category>TeamPCP</category><category>Mini Shai Hulud</category><category>NPM</category><category>PyPI</category><category>Supply Chain Attack</category></item><item><title>TeamPCP Targets SAP npm Packages: Mini Shai-Hulud Supply Chain Attack</title><link>https://runtimerebel.com/blog/teampcp-targets-sap-npm-packages-mini-shai-hulud-supply-chain-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-targets-sap-npm-packages-mini-shai-hulud-supply-chain-attack</guid><description>TeamPCP broadens supply chain attacks, compromising npm packages in SAP&apos;s cloud development ecosystem with the &apos;Mini Shai-Hulud&apos; malicious code injection.</description><pubDate>Fri, 01 May 2026 00:54:59 GMT</pubDate><category>TeamPCP</category><category>SAP</category><category>NPM</category><category>Supply Chain Attack</category><category>Mini Shai Hulud</category><category>Cloud Security</category></item><item><title>Official SAP npm Packages Compromised in TeamPCP Supply Chain Attack</title><link>https://runtimerebel.com/blog/official-sap-npm-packages-compromised-in-teampcp-supply-chain-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/official-sap-npm-packages-compromised-in-teampcp-supply-chain-attack</guid><description>Attackers compromised official SAP npm packages to exfiltrate developer credentials and tokens. Learn how to detect and remediate this supply chain threat.</description><pubDate>Thu, 30 Apr 2026 00:50:55 GMT</pubDate><category>SAP</category><category>NPM</category><category>TeamPCP</category><category>Credential Theft</category><category>Malicious Packages</category></item></channel></rss>