Security News

Cryptocurrency attack thwarted by npm team
2019-06-10 10:36

Cryptocurrency users narrowly escaped losing all their funds last week after an attacker poisoned a digital wallet with malicious code that stole their blockchain access details.

Someone slipped a vuln into crypto-wallets via an NPM package. Then someone else siphoned off $13m in coins to protect it from thieves
2019-06-07 05:56

What a wild ride, eh Komodo? Blockchain biz Komodo this week said it had used a vulnerability discovered by JavaScript package biz NPM to take control of some older Agama cryptocurrency wallets to...

Here's how NPM plans to improve security and reliability in 2019
2018-12-17 12:00

NPM is working to course-correct after 2018 brought a handful of major incidents that caused usability and security headaches for system administrators.

Check your repos... Crypto-coin-stealing code sneaks into fairly popular NPM lib (2m downloads per week)
2018-11-26 20:58

Node.js package tried to plunder Bitcoin wallets A widely used Node.js code library in NPM's warehouse of repositories was altered to include crypto-coin-stealing malware. The lib in question,...

One-in-two JavaScript project audits by NPM tools sniff out at least one vulnerability...
2018-08-22 19:57

...and those devs are then applying patches, we hope JavaScript library custodian NPM, after years of security scrambling, looks to be getting a grip on its code safety.…

Now Pushing Malware: NPM package dev logins slurped by hacked tool popular with coders
2018-07-12 20:13

Tokens killed after eslint-scope JavaScript utility compromised An unfortunate chain reaction was averted today after miscreants tampered with a widely used JavaScript programming tool to steal...

Backdoored Module Removed from npm Registry
2018-05-04 14:38

A malicious package masquerading as a cookie parsing library but delivering a backdoor instead was unpublished from the npm Registry along with three other packages. read more

Attackers Use Typo-Squatting To Steal npm Credentials (Threatpost)
2017-08-04 21:24

Criminals used a typo-squatting technique and uploaded rogue JavaScript libraries to a popular code repository npm.