Install
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Shai-Hulud npm Worm Resurfaces After 111 Days and Slips Past Malware Scanning
4+ day, 19+ hour ago (672+ words) A familiar npm worm has returned after more than three months of silence, carrying the same malicious file linked to an earlier supply-chain incident. The reappearance shows how a known threat can regain access to developer environments when it is…...
Shai-Hulud Malware Returns to npm Unchanged, 111 Days After Its Hash Was Fingerprinted
4+ day, 17+ hour ago (507+ words) Four packages is a small blast radius next to the 639 malicious versions pushed during the May campaign. The significance sits elsewhere. npm rolled out publish-time scanning in July, a control that briefly holds new publications for automated analysis before they…...
ChainDrop npm Worm: 444 Packages Infected in 4 Hours
1+ week, 7+ hour ago (731+ words) Once triggered, the background task restarts the credential-harvesting cycle on the newly infected machine, which is what gives ChainDrop its worm-like, self-sustaining spread across a team or an organization rather than a single compromised build. For command and control, ChainDrop…...
Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
1+ week, 2+ day ago (665+ words) Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads. According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put…...
Mirage Kitten switches to Node.js and JavaScript malware
1+ week, 4+ day ago (1613+ words) While monitoring Mirage Kitten activity, we uncovered a previously undocumented malware family that we dubbed NodeRabbit. We identified the first sample on a system in Afghanistan. Further threat hunting revealed two additional, more advanced, variants: one on a system in…...
Shai-Hulud Trinitite Supply-Chain Worm Hits npm Package With 150K+ Weekly Downloads
1+ week, 5+ day ago (333+ words) The malicious versions use a hidden binding.gyp execution path and a large obfuscated JavaScript loader to infect developer machines and CI environments. The campaign appears linked to the previously reported Shai-Hulud “Mini” worm family, including the Here We Go…...
An attacker infected a popular npm package with over 150,000 downloads per week. How did the malware steal tokens and infect other projects?
1+ week, 6+ day ago (218+ words) A popular developer tool has been infected with malicious code. Aikido researchers discovered ten infected versions of the @7nohe/openapi-react-query-codegen npm package, which is downloaded over 150,000 times a week. Once installed, it could search your computer for keys and access tokens,…...
24 Malicious npm Packages Abuse Trusted Mirrors to Host ClickFix Phishing Pages
2+ week, 3+ day ago (561+ words) Twenty-four malicious npm packages have been used to turn trusted package mirrors into staging points for ClickFix phishing pages. The campaign does not infect a developer by installing a package. Instead, it exploits the confidence users place in familiar hosting…...
24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages
2+ week, 4+ day ago (537+ words) Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. "While the malware is simply a single HTML page inside the npm package,…...
ClickFix Phishing Pages Discovered in 24 npm Packages
2+ week, 4+ day ago (462+ words) OX Security identified and is tracking a fake Cloudflare Captcha campaign that can potentially distribute ClickFix malware through npm, and found 24 distinct malicious packages sharing the exact same malicious code. The OX Research team is tracking a fake Cloudflare campaign…...