https://advisories.gitlab.com/golang/github.com/esm-dev/esm.sh/CVE-2026-23644/
esm.sh has a path traversal in extractPackageTarball enables file writes from malicious packages |...
CVE-2026-23644 esm.sh has a path traversal in extractPackageTarball enables file writes from malicious packages: The commit does not actually fix the path...
path traversalmalicious packagesesmshfile
https://www.sonatype.com/blog/this-week-in-malware-oct-14-22
Over 50 Malicious Packages Identified This Week | Sonatype
This week we discovered and analyzed nearly 5 dozen packages flagged as malicious, suspicious, or dependency confusion attacks in npm and PyPI registries.
malicious packagesthis weekidentifiedsonatype
https://snyk.io/de/blog/malicious-packages-open-source-ecosystems/
The rising trend of malicious packages in open source ecosystems | Snyk
In this article, we want to share a broader picture of how the Snyk security team is monitoring and disclosing security incidents concerning malicious packages.
the risingmalicious packagesopen sourcetrendecosystems
https://securityexpress.info/malicious-packages-found-destroying-data-and-stealing-crypto-keys/
Malicious Packages Found Destroying Data and Stealing Crypto Keys - Tech News
May 6, 2025 - Malicious packages in Go, npm, and PyPI are destroying data on Linux and stealing crypto keys. Developers must verify dependencies and monitor traffic.
malicious packagescrypto keystech newsfounddestroying
https://cyberscoop.com/open-source-security-supply-chain-sonatype/
Malicious packages in open-source repositories are surging | CyberScoop
Oct 10, 2024 - The open-source ecosystem is being overrun by malicious packages, a new report from Sonatype finds.
open source repositoriesmalicious packagescyberscoop
https://me-en.kaspersky.com/about/press-releases/kaspersky-reveals-a-37-increase-in-malicious-packages-compromising-software-supply-chains-worldwide
Kaspersky reveals a 37% increase in malicious packages compromising software supply chains worldwide
Apr 30, 2026 - According to Kaspersky telemetry, almost 19,500 malicious packages were found in open-source projects by the end of 2025, representing a 37% increase compared...
software supply chainsmalicious packageskasperskyrevealsincrease
https://candid.technology/npm-repository-supply-chain-attack-malicious-packages/
Supply chain attack targets NPM repository with malicious packages
Major NPM supply chain attack targets hundreds of popular code libraries, including Puppeteer, threatening developer systems.
supply chain attackmalicious packagestargetsnpmrepository
https://thehackernews.com/2024/07/60-new-malicious-packages-uncovered-in.html?ref=blog.netmanageit.com
60 New Malicious Packages Uncovered in NuGet Supply Chain Attack
Discover how hackers are using sophisticated techniques to inject malware into NuGet packages, targeting developers and compromising software supply c
supply chain attackmalicious packagesnewuncoverednuget
https://ciso.economictimes.indiatimes.com/tag/malicious+packages
Malicious packages - Latest malicious packages , Information & Updates - IT Security -ET CISO
ETCISO.in brings latest malicious packages news, views and updates from all top sources for the Indian IT Security industry.
malicious packageslatest informationit securityupdateset
https://www.cxodigitalpulse.com/60-new-malicious-packages-uncovered-in-nuget-supply-chain-attack/
60 New Malicious Packages Uncovered in NuGet Supply Chain Attack - CXO Digitalpulse
Jul 12, 2024 - Threat actors have been observed publishing a new wave of malicious packages to the NuGet package manager as part of an ongoing campaign that began in August...
supply chain attackmalicious packagesnewuncoverednuget
https://aviatrix.ai/threat-research-center/north-korean-hackers-1700-malicious-packages-supply-chain-attack-2026/
North Korean Hackers Deploy 1,700 Malicious Packages in Supply Chain Attack - 2026
In April 2026, North Korean hackers executed a massive supply chain attack by publishing over 1,700 malicious packages across multiple open-source ecosystems,...
supply chain attacknorth koreanmalicious packageshackersdeploy
https://www.kodemsecurity.com/resources/vulnerability-alert-the-qix-npm-supply-chain-attack-lessons-for-the-ecosystem
Malicious Packages Alert: The Qix npm Supply-Chain Attack: Lessons for the Ecosystem | Kodem
The npm ecosystem is in the middle of a major supply-chain compromise. The maintainer known as Qix is currently targeted in a phishing campaign that allows...
supply chain attackmalicious packagesalertqixnpm
https://cyberwebspider.com/cyber-security-news/malicious-npm-packages-as-utilities-let-attackers-destroy-production-systems/
Malicious npm Packages as Utilities Let Attackers Destroy Production Systems - Cyber Web Spider...
Jun 9, 2025 - Safety researchers have uncovered a disturbing new risk within the npm ecosystem the place malicious packages masquerade as authentic utilities whereas
npm packagesproduction systemsmaliciousutilitieslet
https://c-suite.exchange/malicious-laravel-packages-on-packagist-deploy-cross-platform-remote-access-trojan/
Malicious Laravel Packages On Packagist Deploy Cross Platform Remote Access Trojan - C-Suite...
Mar 5, 2026 - Security researchers discovered malicious Laravel related packages on Packagist that deploy a cross platform remote access trojan affecting Windows, macOS, and...
laravel packagescross platformremote accessmaliciouspackagist
https://portscanner.online/news/2025/malicious-npm-packages-exploit-ethereum-smart-contracts-to-target-crypto-developers.html
Malicious npm Packages Exploit Ethereum Smart Contracts to Target Crypto Developers - Online Port...
ethereum smart contractsnpm packagesmaliciousexploittarget
https://nquiringminds.com/cybernews-summaries/ab746e304ca994537cd37838aacbc85b/
Checkmarx Warns of Unknown Threat Actor Targeting Developers with Malicious npm Packages |...
threat actornpm packagescheckmarxwarnsunknown
https://www.cybermaterial.com/p/malicious-go-packages-target-linux-and-macos
Malicious Go Packages Target Linux and macOS
Cybersecurity researchers have raised alarms about an ongoing malicious campaign targeting the Go ecosystem, specifically involving typosquatted modules that...
maliciousgopackagestargetlinux
https://heimdalsecurity.com/blog/malicious-pypi-packages-used-to-mine-cryptocurrency/
Multiple Malicious PyPI Packages Used to Mine Cryptocurrency
Jun 23, 2021 - Malicious PyPI packages caught in the repository for Python projects were turning the developers' workstations into cryptomining machines.
used tomultiplemaliciouspypipackages
https://www.endorlabs.com/learn/whatfuscator-malicious-open-source-packages-and-other-beasts
Whatfuscator, Malicious Open Source Packages, and Other Beasts | Blog | Endor Labs
Join Henrik to learn how his journey into Go programming turned into a path of malicious OSS packages.
open source packagesendor labsmaliciousbeastsblog