https://blog.netmanageit.com/trust-wallet-links-8-5-million-crypto-theft-to-shai-hulud-npm-attack/
Trust Wallet links $8.5 million crypto theft to Shai-Hulud NPM attack
Jan 2, 2026 - Trust Wallet believes the compromise of its web browser to steal roughly $8.5 million from over 2,500 crypto wallets is likely related to an "industry-wide"...
trust walletshai huludnpm attacklinksmillion
https://threatlabsnews.xcitium.com/blog/trust-wallet-8-5m-crypto-theft-traced-to-shai-hulud-npm-attack/
Trust Wallet $8.5M Crypto Theft Traced to Shai-Hulud NPM Attack - threatlabsnews.xcitium.com
Feb 6, 2026 - The browser extension of the Trust Wallet was compromised by a supply chain worm attack; hence, 2,500+ wallets lost $8.5 million. Discover how the Shai-Hulud...
trust walletshai huludnpm attackcryptotheft
https://emailexpert.com/the-npm-attack-a-marketing-technology-wake-up-call/
The npm Attack: A Marketing Technology Wake-up Call | emailexpert
This past week a sophisticated phishing attack on a maintainer of several popular npm packages led to the brief compromise of at least 18 widely used...
wake up callnpm attackmarketing technology
https://xcp-ng.org/forum/topic/12041/axios-npm-attack
Axios NPM attack | XCP-ng and XO forum
Apr 1, 2026 - As XO is using npm I wonder after reading this: https://thehackernews.com/2026/04/google-attributes-axios-npm-supply.html Is there something we need to check...
npm attackaxiosxcpngxo
https://securitybrief.news/story/ledger-warns-of-npm-attack-thwarted-by-malware-coding-errors
Ledger warns of NPM attack thwarted by malware coding errors
Ledger warned of a major NPM supply chain attack targeting cryptocurrency wallets, thwarted due to malware coding errors preventing widespread fund theft.
npm attackledgerwarnsthwartedmalware
https://bitcoinmagazine.com/news/npm-attack-javascript-library-compromise-goes-after-bitcoin-wallets
NPM Attack: Javascript Library Compromise Goes After Bitcoin Wallets
Sep 8, 2025 - NPM developer qix's account compromise potentially puts user funds at risk by compromising library dependencies used by bitcoin wallets.
npm attackjavascript librarybitcoin walletscompromisegoes
https://thehackernews.com/2023/04/hackers-flood-npm-with-bogus-packages.html
Hackers Flood NPM with Bogus Packages Causing a DoS Attack
dos attackhackersfloodnpmbogus
https://www.veracode.com/blog/ledger-phishing-attack-connect-kit/
Ledger npm Repo Breached in Spear Phishing Attack | Veracode
Jun 4, 2025 - Application Security for the AI Era | Veracode
spear phishingledgernpmrepoattack
https://thecyberwire.com/newsletters/privacy-briefing/4/128
More on the apparent Shanghai National Police data breach. Supply chain attack on NPM package...
More on the apparent Shanghai National Police data breach. Supply chain attack on NPM package manager. Marriott confirms data breach of hotel guest and...
supply chain attackmore onpolice datanpm packageapparent
https://www.nlcyber.com/all/news/bitwarden-npm-package-hit-in-supply-chain-attack
Bitwarden NPM Package Hit in Supply Chain Attack
Tied to a fresh Checkmarx supply chain attack claimed by TeamPCP, the incident references the Shai-Hulud worm. The post Bitwarden NPM Package Hit in Supply Chai
supply chain attacknpm packagebitwardenhit
https://www.kodemsecurity.com/resources/the-shai-hulud-worm-returns-new-npm-supply-chain-attack-compromises-sap-packages
Shai-Hulud Worm Returns: SAP npm Supply Chain Attack
The Shai-Hulud worm targets SAP npm packages via preinstall scripts. See affected packages, IOCs, and detection guidance for this supply chain attack.
supply chain attackshai huludwormreturnssap
https://cloud.google.com/blog/topics/threat-intelligence/north-korea-threat-actor-targets-axios-npm-package
North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack |...
A North Korea-nexus threat actor targeted the popular axios NPM package in a massive supply chain attack.
supply chain attacknorth koreathreat actornpm packagenexus
https://www.threatlocker.com/blog/axios-supply-chain-attack-how-a-compromised-npm-package-delivered-rat-malware
Axios supply chain attack: How a compromised npm package delivered RAT malware
A malicious Axios npm release compromised over 10,000 systems in hours. Learn how the attack worked, the IoCs, and how to prevent supply chain attacks.
supply chain attacknpm packageaxioscompromiseddelivered
https://thecybertrove.com/npm-supply-chain-attack-hugging-face-malware/
npm Supply Chain Attack Exploits Hugging Face Malware
Apr 23, 2026 - npm supply chain attack abuses Hugging Face for malware delivery and data theft, exposing cross-platform implants and exfiltration risks.
supply chain attackhugging facenpmexploitsmalware
https://www.malwarebytes.com/blog/news/2026/03/axios-supply-chain-attack-chops-away-at-npm-trust?ref=christophermoravec.com
Axios supply chain attack chops away at npm trust | Malwarebytes
Mar 31, 2026 - Developers using the axios package from npm may have downloaded a malicous version that drops a Remote Access Trojan
supply chain attackaxioschopsawaynpm