Hackers have injected credential-stealing malware into newly published versions of node-ipc, a popular inter-process communication package, in a new supply chain attack targeting npm. The node-ipc ...
Attackers performed an email takeover attack on a dormant maintainer account and published new node-ipc versions containing ...
Threat actors earlier today published more than 600 malicious packages to the Node Package Manager (npm) index as part of a ...
Hulud payload to steal CI/CD secrets from Linux-based automation environments. The malware executes during npm install and ...