News

On September 8, 2025, a single phishing email triggered one of npm’s most damaging supply chain attacks, compromising 18 ...
The credential stealer harvested username, password, and 2FA codes before sending them to a remote host. With full access, ...
Binance reassures customers after a massive NPM supply chain attack injects malicious code into 18 popular JavaScript ...
A recent supply chain hack has seen malware injected into NPM packages with over 2.6Bn weekly downloads after compromising a maintainer’s account in a phishing attack. The NPM attack is causing a lot ...
"debug" package attack failed; malicious update detected early, minimal impact. Developers urged to check their installations ...
More companies are moving to integrate custom AI agents into business operations. Here are eight essential capabilities to ...
Npm packages are reusable blocks of JavaScript code published to the Node Package Manager registry that developers can ...
A new digital supply chain attack has targeted popular open-source npm packages with at least two billion downloads per week. On Sept. 8, Josh Junon, a package maintainer whose account was at the ...
According to ReversingLabs' 2025 Software Supply Chain Security Report, 14 of the 23 crypto-related malicious campaigns in ...
A JavaScript supply chain attack has delivered a crypto-clipper via 18 npm packages; Ledger’s CTO has warned ...
In a supply chain attack, attackers have injected malware into NPM packages with over 2.6 billion weekly downloads after ...
Vibe coding. It's a term that's bubbling around to describe a new wave of app creation. It means instead of writing code line ...