Threats Tagged 'npm compromise'
View all threats tagged with 'npm compromise'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'npm compromise'
Click on any threat for detailed analysis and mitigation recommendations
Supply Chain Compromise Affecting keyv and cacheable npm Packages 0 A supply chain attack has compromised the keyv and cacheable npm packages by injecting malicious preinstall hooks into at least ten packages. The attack started with the compromise of a maintainer account, enabling the threat actor to distribute malware that harvests cloud and CI credentials from multiple platforms. The malware self-propagates by repackaging other npm packages with the malicious code and republishing them using stolen tokens. Stolen credentials are exfiltrated to attacker-controlled GitHub repositories, and persistence mechanisms are established in developer directories. This campaign affects tens of millions of weekly downloads and targets developer environments and cloud infrastructure credentials. Join the discussion | AlienVault OTX General | 08/05/2026, 08:15:06 UTC Added: 08/05/2026, 08:56:25 UTC |
Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery 0 On July 14, 2026, a coordinated supply chain attack compromised the @asyncapi npm organization, affecting five package versions across four packages. The attack originated from a GitHub Actions workflow vulnerability that exposed privileged credentials, enabling unauthorized code injection. Unlike typical postinstall attacks, this campaign executes at module import time, bypassing common npm install --ignore-scripts protections. The malicious code spawned hidden processes that fetched a second-stage payload from IPFS, deploying the Miasma modular runtime with command-and-control capabilities, persistence mechanisms, and credential harvesting features. The payload included disabled modules for supply-chain propagation, AI-tool poisoning, and sandbox evasion. All compromised packages were published through legitimate GitHub OIDC workflows with valid provenance signatures, masking the malicious activity within trusted release processes. Join the discussion | AlienVault OTX General | 07/16/2026, 06:59:08 UTC Added: 07/16/2026, 10:47:58 UTC |
jscrambler npm Package Compromised in Supply Chain Attack 0 A malicious release of the jscrambler npm package (version 8.14.0) was published on July 11, 2026, introducing hidden native binaries that execute automatically during installation. The compromised package added an undocumented preinstall hook executing dist/setup.js, which deploys platform-specific binaries for Linux, macOS, and Windows embedded in an obfuscated CSI container. The payload is a Rust-built infostealer targeting cryptocurrency wallets, AI coding assistants, cloud credentials (AWS, GCP, Azure), browser data, and messaging applications. String obfuscation uses per-string ChaCha20-Poly1305 encryption. The threat actor published five malicious versions (8.14.0, 8.16.0, 8.17.0, 8.18.0, 8.20.0) over three hours, evolving delivery methods to evade detection. Version 8.22.0 is confirmed clean. The package receives approximately 15,800 weekly downloads, affecting developer workstations, CI systems, and build pipelines with access to credentials and secrets. Join the discussion | AlienVault OTX General | 07/11/2026, 23:55:30 UTC Added: 07/13/2026, 10:32:46 UTC |
Compromised Injective SDK npm Package Exfiltrates Wallet Keys and Mnemonics 0 A compromised version of the Injective Labs TypeScript SDK npm package was published containing malicious code that exfiltrates cryptocurrency wallet private keys and mnemonic phrases. The malicious version 1.20.21 was published on June 8, 2026, through a compromised developer account with established repository access. The malware hooks key generation functions to capture sensitive wallet data and exfiltrates it via base64-encoded POST requests to legitimate Injective infrastructure endpoints, disguising the traffic. The threat actor amplified impact by publishing 17 additional scoped packages pinned to the malicious version. Though quickly detected and contained within hours, the compromised package received approximately 310 downloads. The package has roughly 50,000 weekly downloads and 87 dependent packages, presenting significant supply chain risk to cryptocurrency wallet implementations. Join the discussion | AlienVault OTX General | 07/10/2026, 03:46:31 UTC Added: 07/10/2026, 07:47:32 UTC |
Showing 1 to 4 of 4 results