Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

Shattered
shattered.io > chaindrop-npm-worm-444-packages-2026

ChainDrop npm Worm: 444 Packages Infected in 4 Hours

1+ week, 11+ hour ago   (731+ words) Once triggered, the background task restarts the credential-harvesting cycle on the newly infected machine, which is what gives ChainDrop its worm-like, self-sustaining spread across a team or an organization rather than a single compromised build. For command and control, ChainDrop…...

dev.ua
dev.ua > en > news > populiarnyi-npm-paket-iz-virusom-1788081822

An attacker infected a popular npm package with over 150,000 downloads per week. How did the malware steal tokens and infect other projects?

1+ week, 6+ day ago   (218+ words) A popular developer tool has been infected with malicious code. Aikido researchers discovered ten infected versions of the @7nohe/openapi-react-query-codegen npm package, which is downloaded over 150,000 times a week. Once installed, it could search your computer for keys and access tokens,…...

gbhackers.com
gbhackers.com > hackers-compromise-tanstack-query-npm-package > amp

Hackers Compromise TanStack Query npm Package to Steal Developer Credentials

2+ week, 22+ hour ago   (467+ words) Aikido Security said it identified 10 malicious versions published within 20 minutes. Because the package records more than 150,000 weekly downloads, the incident poses exposure risk to development teams. The compromise affected npm and the project’s GitHub repository. Attackers are believed to have…...

Google News
stepsecurity.io > blog > 7nohe-openapi-react-query-codegen-compromised-npm-publishing-workflow

@7nohe/openapi-react-query-codegen Compromised Through an Exposed npm Publishing Workflow

2+ week, 1+ day ago   (602+ words) The attacker did not need a maintainer npm password or a long lived npm token. The repository accepted an npm publish comment from any pull request participant, checked out that pull request, installed its dependencies, and published packages with a…...

gbhackers.com
gbhackers.com > fake-cloudflare-clickfix-pages > amp

Hackers Turn Trusted npm Mirrors Into Hosts for Fake Cloudflare ClickFix Pages.

2+ week, 3+ day ago   (665+ words) Threat actors are abusing npm’s package-distribution ecosystem to host convincing fake Cloudflare verification pages on trusted mirror domains, turning developer infrastructure into a phishing delivery layer. OX Security said it identified 24 malicious npm packages containing identical HTML code designed to…...

The Hacker News
thehackernews.com > 2026 > 08 > 24-npm-packages-abuse-unpkg-mirrors-to.html

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

2+ week, 4+ day ago   (537+ words) Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. "While the malware is simply a single HTML page inside the npm package,…...

Google News
csoonline.com > article > 4212381 > backdoored-rust-packages-hit-crates-io-exposing-developers-to-malware-at-build-time.html

Backdoored Rust packages hit crates.io, exposing developers to malware at build time | CSO Online

3+ week, 1+ day ago   (486+ words) Malicious versions of three Rust packages, including the widely used arrayref, were published to the crates.io registry on August 20, carrying a backdoor that executed automatically when affected projects were compiled. Security researchers at Wiz said the attack also shares…...

gbhackers.com
gbhackers.com > chaindrop-exploits-npm

ChainDrop Publishes Initial Malware Without Stealing a Long-Lived npm Token

3+ week, 5+ day ago   (512+ words) The ChainDrop campaign has exposed a gap in modern software supply-chain defenses: malware no longer needs a durable npm publishing token or even an npm install event to spread through developer environments. The self-propagating npm worm, also tracked as a…...

The Hacker News
thehackernews.com > 2026 > 08 > 16-typosquatted-rubygems-packages-steal.html

16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets

3+ week, 4+ day ago   (668+ words) OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker. The complete list of packages published as part of the campaign is below - The 16 gems have been published by users named "mod8rz41mje" (aka Riley Miller) and…...