Image with text "281 malicious package versions, Miasma Returns"

New Shai-Hulud Miasma Wave Hits Hundreds of npm Packages

TL;DR Sonatype Security Research is tracking a new Shai-Hulud Miasma wave with 281 malicious npm package versions that move beyond obvious preinstall and postinstall scripts in package.json. This variant abuses binding.gyp to ...
Image with text "Lazarus Group, Trust Abuse on npm" at center and a label of "breaking news" in the upper right-hand corner.

Lazarus Group’s Latest: Brandjacking Campaign on npm

TL;DR Sonatype Security Research is tracking a Lazarus Group npm campaign using dozens of malicious packages to abuse developer trust and deliver follow-on payloads. The campaign goes beyond typosquatting, relying on brandjacking ...
Red Hat Cloud Services npm Packages Hijacked

Red Hat Cloud Services npm Packages Hijacked

A new wave of malicious npm activity has been reported involving multiple packages in the legitimate @redhat-cloud-services namespace ...

Axios Compromise on npm Introduces Hidden Malicious Package

A newly discovered software supply chain attack targeting the npm ecosystem briefly compromised one of the most widely used JavaScript libraries in the world ...
Sonatype Discovers Two Malicious npm Packages

Sonatype Discovers Two Malicious npm Packages

Sonatype Security Research has identified a potential compromise of a trusted npm maintainer account that has now published two malicious npm packages — sbx-mask and touch-adv — designed to exfiltrate secrets from ...
Hijacked npm Packages Deliver Malware via Solana, Linked to Glassworm

Hijacked npm Packages Deliver Malware via Solana, Linked to Glassworm

Sonatype Security Research has identified two hijacked npm packages in the React Native ecosystem that receive more than 30,000 downloads collectively per week and were modified to deliver multi-stage malware. Sonatype is ...
SANDWORM_MODE: The Rise of Adaptive Supply Chain Worms

SANDWORM_MODE: The Rise of Adaptive Supply Chain Worms

Earlier this year, we asked our team where they expect open source cyberattacks to go next. Sonatype Principal Security Researcher Garrett Calpouzos shared his thoughts about how he anticipated attackers won't simply ...
SANDWORM_MODE: The Rise of Adaptive Supply Chain Worms

SANDWORM_MODE: The Rise of Adaptive Supply Chain Worms

Earlier this year, we asked our team where they expect open source cyberattacks to go next. Sonatype Principal Security Researcher Garrett Calpouzos shared his thoughts about how he anticipated attackers won't simply ...

PhantomRaven: npm Malware Evolves Again

Published 3:00 p.m. ET on October 31, 2025; last updated 5:00 p.m. ET on October 31, 2025 This week, an open source malware campaign dubbed ‘PhantomRaven’ has run rampant, flooding the npm ...