This is the second installment of my series on building an "autonomous conversational and execution AI assistant."This time, ...
A credential stealer called sckit hooked into MemTensor MemOS at the runtime level — bypassing install-time scanners, ...
How many people actually look at the contents of a package before running `npm install`?Most people just look at the name and ...
On Sep 23, 2026, security researchers reported that unknown threat actors compromised two legitimate MemTensor packages on ...
Malicious npm package tw-pkgprobe-7731 targets Twilio developer environments and can exfiltrate credentials and environment ...
Attackers have successfully exploited a supply chain attack by abusing npm’s trusted publishing mechanism to distribute a previously unknown malware loader called GHAPPIER within a legitimate package, ...
The NPM ecosystem has suffered another supply chain attack in which a malicious package has accumulated millions of downloads ...
Malicious npm package indexed-btree hid its loader in runtime code, avoiding install hooks after logging millions of downloads.
CloudSEK traced GHAPPIER across at least 65 public repositories, 73 infected files and 22 accounts. A second payload in another victim's repository exactly matched PolinRider, a campaign ...
A malicious npm package reached over 2 million weekly downloads by hiding its payload in a routine library function rather than an install script.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results