https://www.bleepingcomputer.com/news/security/new-wave-of-fake-interviews-use-35-npm-packages-to-spread-malware/
A new wave of North Korea's 'Contagious Interview' campaign is targeting job seekers with malicious npm packages that infect dev's devices with infostealers...
new wavenpm packagesuse
https://codeberg.org/freesewing/freesewing
freesewing - Freesewing's monorepo holding all our NPM packages, including our core library
monorepoholdingnpm
https://docs.npmjs.com/adding-dist-tags-to-packages/
Documentation for the npm registry, website, and command-line interface
addingdisttagspackagesnpm
https://www.theregister.com/2025/11/14/selfreplicating_supplychain_attack_poisons_150k/
Nov 14, 2025 - : Amazon spilled the TEA
crimsfloodnpmjunkpackages
https://github.com/kevinslin/safe-npm?cmid=68bbf2b5-2b82-42a2-af26-84f1fb3dc2e4
Safely install NPM packages. Contribute to kevinslin/safe-npm development by creating an account on GitHub.
githubsafenpminstallpackages
https://www.bleepingcomputer.com/news/security/shai-hulud-malware-infects-500-npm-packages-leaks-secrets-on-github/
Hundreds of trojanized versions of well-known packages such as Zapier, ENS Domains, PostHog, and Postman have been planted in the npm registry in a new...
npm packagesshaimalwareinfectsleaks
https://itsmycode.com/unable-to-resolve-dependency-tree-error-when-installing-npm-packages/
Oct 19, 2024 - The Unable to resolve dependency tree error when installing npm packages occurs when you install the node dependencies with the latest version of NPM(v7).
npm packagesunableresolvedependencytree
https://forwardemail.net/en/blog/docs/how-npm-packages-billion-downloads-shaped-javascript-ecosystem
In the JavaScript and Node.js world, some packages are essential—downloaded millions of times daily and powering apps worldwide. Behind these tools are...
npm packagesdecadeimpacthit
https://www.csoonline.com/article/4115417/malicious-npm-packages-target-n8n-automation-platform-in-a-supply-chain-attack.html
Jan 12, 2026 - Researchers discovered malicious npm packages posing as n8n integrations, exfiltrating OAuth tokens and API keys from enterprise workflows.
npm packagesautomation platformmalicioustarget
https://arethetypeswrong.github.io/
Are The Types Wrong? - Tool for analyzing TypeScript types of npm packages
typeswrongtoolanalyzing
https://www.csoonline.com/article/4050956/malicious-npm-packages-use-ethereum-blockchain-for-malware-delivery.html
Sep 3, 2025 - Ethereum smart contracts used to hide URL to secondary malware payloads in an attack chain triggered by a malicious GitHub repo.
npm packagesethereum blockchainmalicioususemalware
https://jfrog.com/blog/shai-hulud-npm-supply-chain-attack-new-compromised-packages-detected/
Dec 2, 2025 - Learn about the ongoing Shai Hulud npm supply chain attack, including all currently known compromised packages
supply chain attackshainpmnewcompromised
https://deno.com/blog/v2.3
Deno 2.3 adds new features for deno compile and deno fmt, support for using local npm packages, several performance improvements, and more. Here are the...
npm packagesdenoimprovedcompilelocal
https://www.pika.dev/
Find modern, web-ready packages on npm. Get faster, smaller JavaScript bundles.
pikasearchnpmfastmodern
https://arstechnica.com/security/2025/10/npm-flooded-with-malicious-packages-downloaded-more-than-86000-times/
Oct 30, 2025 - Packages downloaded from NPM can fetch dependencies from untrusted sites.
npmfloodedmaliciouspackagesdownloaded
https://www.csoonline.com/article/4028412/supply-chain-attack-compromises-npm-packages-to-spread-backdoor-malware.html
Jul 24, 2025 - Phishing attacks on package maintainer accounts led to infected JavaScript type testing utilities.
supply chain attacknpm packagescompromisesspreadbackdoor
https://sqmagazine.co.uk/shai-hulud-npm-attack-zapier-postman-exposed/
Nov 24, 2025 - Shai-Hulud malware hits Zapier, ENS, and Postman, infecting 500+ npm packages and leaking thousands of developer secrets to GitHub.
zapierpostmanenshitshai
https://www.aikido.dev/blog/npm-supply-chain-phishing-campaigns
A targeted spear-phishing campaign used npm packages and jsDelivr as free phishing infrastructure, serving custom credential harvesters per victim
npm packagesgoneservingcustomcredential
https://www.reversinglabs.com/news/techradar-new-attacks-exploit-vscode-extensions-and-npm-packages
Developers targeted by malicious Microsoft VSCode extensions
npm packagestechradarnewattacksexploit
https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised
The popular packages debug and chalk on npm have been compromised with malicious code
npmdebugchalkpackagescompromised
https://dev.to/opctim/a-small-script-to-detect-sha1-hulud-20-affected-packages-in-npm-projects-3le9
Nov 25, 2025 - As of November 25th, 2025, the Shai Hulud 2 supply-chain incident is still in the process of being... Tagged with security, shaihulud, npm.
smallscriptdetectaffected
https://www.infoworld.com/article/4086337/malicious-npm-packages-contain-vidar-infostealer.html
Nov 6, 2025 - Researchers say the malware was in the repository for two weeks, advise precautions to defend against malicious packages.
npm packagesmaliciouscontaininfostealerinfoworld
https://securelist.com/shai-hulud-worm-infects-500-npm-packages-in-a-supply-chain-attack/117547/
Oct 15, 2025 - We dissect a recent incident where npm packages with millions of downloads were infected by the Shai-Hulud worm. Kaspersky experts describe the starting point...
npm packagesshaiworminfectssecurelist
https://www.aikido.dev/blog/introducing-safe-chain
Safe-Chain by Aikido is a powerful tool to prevent installing any malicious package version by verifying each package with the Aikido Intel database and...
npm packagesintroducingsafechainstopping
https://www.silvestar.codes/articles/my-favorite-npm-packages/
I’ve compiled a list of my favorite npm packages that I use on a daily basis.
npm packagesfavorite
https://www.csoonline.com/article/4082195/malicious-packages-in-npm-evade-dependency-detection-through-invisible-url-links-report.html
Oct 30, 2025 - Researchers outline how the PhantomRaven campaign exploits hole in npm to enable software supply chain attacks.
maliciouspackagesnpmevadedependency
https://www.csoonline.com/article/4026380/prettier-eslint-npm-packages-hijacked-in-a-sophisticated-supply-chain-attack.html
Jul 22, 2025 - DLL-based malware targets Windows users after a phishing campaign tricked the maintainer into leaking a token.
npm packagessupply chainprettiereslinthijacked
https://www.bleepingcomputer.com/news/security/self-propagating-supply-chain-attack-hits-187-npm-packages/
Security researchers have identified at least 187 npm packages compromised in an ongoing supply chain attack. The coordinated worm-style campaign dubbed...
supply chain attacknpm packagesselfhits
https://www.zscaler.com/blogs/security-research/malicious-npm-packages-deliver-nodecordrat
Jan 7, 2026 - ThreatLabz identified malicious NPM packages that deliver NodeCordRAT, which performs credential theft and steals cryptocurrency wallet data.
npm packagesmaliciousdeliver
https://safedep.io/malicious-npm-packages-hyatt-campaign/
Three malicious npm packages disguised as Hyatt internal dependencies were discovered using install hooks to execute malicious payloads. All packages share...
npm packagesreal timemalicioushyattinternal