North Korean hackers published backdoored versions of the Axios NPM package using a compromised long-lived access token.
Attackers stole a long-lived npm token from the lead axios maintainer and published two poisoned versions that drop a ...
A threat actor has used 36 malicious NPM packages posing as Strapi plugins to distribute malware targeting Redis, Docker, and ...
Axios 1.14.1 and 0.30.4 injected malicious plain-crypto-js@4.2.1 after npm compromise on March 31, 2026, deploying ...
Researchers have discovered multiple npm packages named after NodeJS libraries that even pack a Windows executable that resembles NodeJS but instead drops a sinister trojan. These packages, given ...
Two code packages named "nodejs-encrypt-agent" in the popular npm JavaScript library and registry recently were discovered containing the open source information-stealing TurkoRat malware. Researchers ...
Further, Deno 1.26 updates the Node.js streams implementation to use the readable-stream@4.1.0 NPM module, allowing Deno to better keep up with breaking changes and new features. Within this ...