News
JavaScript packages with billions of downloads were compromised by an unknown threat actor looking to steal cryptocurrency.
6d
Cryptopolitan on MSNLedger CTO Charles Guillemet: avoid crypto transactions, supply chain attack discovered
Ledger's CTO Charles Guillemet warned of a large-scale supply chain attack, potentially stealing crypto from common software ...
Malware hidden in widely used libraries like chalk and debug hijacked crypto transactions via browser APIs, exposing deep ...
A successful phishing attack against a developer has resulted in one of the largest supply chain compromises to date, adding ...
Billions (No, that's not a typo, Billions with a capital B) of files were potentially compromised. If you thought Node Package Manager (npm), the Billions of downloads were potentially compromised ...
Qix is an open source maintainer account that was compromised by a phishing attack. This allowed attackers to infect 18 popular npm packages with malicious code. Together, these packages are ...
Multiple npm packages have been compromised by a phishing attack in an attempt to spread crypto malware to billions of victims.
"debug" package attack failed; malicious update detected early, minimal impact. Developers urged to check their installations ...
Overview Coding communities in 2025 give developers worldwide a chance to practice, solve problems, and share ...
In a supply chain attack, attackers injected malware into NPM packages with over 2.6 billion weekly downloads after ...
On September 8, 2025, a single phishing email triggered one of npm’s most damaging supply chain attacks, compromising 18 ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results