Security News

Ripple NPM supply chain attack hunts for private keys
2025-04-23 18:28

A mystery thief and a critical CVE involved in crypto cash grab Many versions of the Ripple ledger (XRPL) official NPM package are compromised with malware injected to steal cryptocurrency.…

Ripple's xrpl.js npm Package Backdoored to Steal Private Keys in Major Supply Chain Attack
2025-04-23 07:17

The Ripple cryptocurrency npm JavaScript library named xrpl.js has been compromised by unknown threat actors as part of a software supply chain attack designed to harvest and exfiltrate users'...

Rogue npm Packages Mimic Telegram Bot API to Plant SSH Backdoors on Linux Systems
2025-04-19 15:11

Cybersecurity researchers have uncovered three malicious packages in the npm registry that masquerade as a popular Telegram bot library but harbor SSH backdoors and data exfiltration capabilities....

Malicious npm Package Targets Atomic Wallet, Exodus Users by Swapping Crypto Addresses
2025-04-10 12:58

Threat actors are continuing to upload malicious packages to the npm registry so as to tamper with already-installed local versions of legitimate libraries to execute malicious code in what's seen...

North Korean Hackers Deploy BeaverTail Malware via 11 Malicious npm Packages
2025-04-05 14:23

The North Korean threat actors behind the ongoing Contagious Interview campaign are spreading their tentacles on the npm ecosystem by publishing more malicious packages that deliver the BeaverTail...

Nine-Year-Old npm Packages Hijacked to Exfiltrate API Keys via Obfuscated Scripts
2025-03-28 06:06

Cybersecurity researchers have discovered several cryptocurrency packages on the npm registry that have been hijacked to siphon sensitive information such as environment variables from compromised...

Infostealer campaign compromises 10 npm packages, targets devs
2025-03-27 20:22

Ten npm packages were suddenly updated with malicious code yesterday to steal environment variables and other sensitive data from developers' systems. [...]

Malicious npm Package Modifies Local 'ethers' Library to Launch Reverse Shell Attacks
2025-03-26 12:00

Cybersecurity researchers have discovered two malicious packages on the npm registry that are designed to infect another locally installed package, underscoring the continued evolution of software...

New npm attack poisons local packages with backdoors
2025-03-26 12:00

Two malicious packages were discovered on npm (Node package manager) that covertly patch legitimate, locally installed packages to inject a persistent reverse shell backdoor. [...]

North Korean Lazarus hackers infect hundreds via npm packages
2025-03-11 20:42

Six malicious packages have been identified on npm (Node package manager) linked to the notorious North Korean hacking group Lazarus. [...]