Image with text "281 malicious package versions, Miasma Returns"

New Shai-Hulud Miasma Wave Hits Hundreds of npm Packages

TL;DR Sonatype Security Research is tracking a new Shai-Hulud Miasma wave with 281 malicious npm package versions that move beyond obvious preinstall and postinstall scripts in package.json. This variant abuses binding.gyp to ...
Image with text "Lazarus Group, Trust Abuse on npm" at center and a label of "breaking news" in the upper right-hand corner.

Lazarus Group’s Latest: Brandjacking Campaign on npm

TL;DR Sonatype Security Research is tracking a Lazarus Group npm campaign using dozens of malicious packages to abuse developer trust and deliver follow-on payloads. The campaign goes beyond typosquatting, relying on brandjacking ...
Red Hat Cloud Services npm Packages Hijacked

Red Hat Cloud Services npm Packages Hijacked

A new wave of malicious npm activity has been reported involving multiple packages in the legitimate @redhat-cloud-services namespace ...
Image with a skull icon alongside text "CanisterSprawl: Self-propagating malware on npm"

Self-Propagating npm Malware Turns Trusted Packages Into Attack Paths

TL;DR An open source malware campaign dubbed CanisterSprawl has been observed in npm, stealing sensitive data from developer machines including tokens, API keys, and more. From there, the malware publishes additional compromised ...

Axios Front-End Library npm Supply Chain Poisoning Alert

Overview On March 31, NSFOCUS CERT detected that the npm repository of the HTTP client library Axios was poisoned by the supply chain. The attacker bypassed the normal GitHub Actions CI/CD pipeline ...

Axios Compromise on npm Introduces Hidden Malicious Package

A newly discovered software supply chain attack targeting the npm ecosystem briefly compromised one of the most widely used JavaScript libraries in the world ...
An Evolving GlassWorm Malware is Making the Rounds of Code Repositories

An Evolving GlassWorm Malware is Making the Rounds of Code Repositories

The bad actor can now deploy a RAT, is targeting MCP servers, and is finding new ways to move through Open VSX ...
Security Boulevard
Sonatype Discovers Two Malicious npm Packages

Sonatype Discovers Two Malicious npm Packages

Sonatype Security Research has identified a potential compromise of a trusted npm maintainer account that has now published two malicious npm packages — sbx-mask and touch-adv — designed to exfiltrate secrets from ...
Hijacked npm Packages Deliver Malware via Solana, Linked to Glassworm

Hijacked npm Packages Deliver Malware via Solana, Linked to Glassworm

Sonatype Security Research has identified two hijacked npm packages in the React Native ecosystem that receive more than 30,000 downloads collectively per week and were modified to deliver multi-stage malware. Sonatype is ...