An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by ...
GitHub's npm registry shipped staged publishing in May 2026, the first mandatory 2FA human checkpoint in its 16-year history, ...
CrowdSec says a TanStack-linked GitHub token was used to copy about 170 private repositories from a former employee’s account ...
Thirteen npm packages deliver WeaselBiscuit, a JavaScript stealer that harvests Chrome extension storage across Windows, macOS, and Linux.
GitHub has announced the general availability of three significant improvements to npm (Node Package Manager), aiming to make using the software more secure and manageable. In summary, the new ...
Researchers find attackers now infect widely used package at runtime, sidestepping recent lifecycle-script restrictions entirely. chaeckmarx ## A New Evasion Technique Emerges ...
npm granular access tokens configured to bypass 2FA can no longer create tokens, change maintainers, or manage org membership as of July 31, 2026 — closing the attack chain TeamPCP exploited across ...
CrowdStrike links PhantomRaven malware to a bug bounty hunter, finding LLM-generated code, malicious npm packages and ...