Threat actors compromised AsyncAPI packages and weaponized trusted CI/CD workflows to distribute malware through npm. This ...
Malicious Jscrambler NPM package versions distributed a cross-platform credential stealer in a new supply chain attack.
Vivani said it expects to begin a Phase 1, randomised, first-in-human study of NPM-139 in mid-2026, using Novo Nordisk's ...
The Jscrambler client-side web security company disclosed that a threat actor published a malicious version of its npm ...
Malicious jscrambler 8.14.0 runs hidden binaries during npm install on Windows, macOS, and Linux, with no fix available as of ...
Injective has dismissed concerns that user funds were compromised after attackers planted wallet-key-stealing code in 18 of ...
Injective says the npm supply chain issue was resolved before downloads, with zero user funds at risk or compromised.
TypeScript 7.0 is now stable after Microsoft ported the entire compiler to Go, delivering build-time speedups of 8x to 12x ...
Hackers compromised the Injective Labs SDK project's GitHub repository and used it to publish a malicious package on the Node ...
Vivani Medical Inc, an innovative, biopharmaceutical company developing novel, ultra long-acting drug implants, announced the signing of a new agreement with Novo Nordisk to enable Novo Nordisk to ...
TL;DR At the end of Q2 2026, Sonatype Research reached 1.8 million malicious packages logged. In Q2, npm accounted for 96.6% ...
GitHub releases npm 12 with install scripts off by default and begins phasing out 2FA bypass tokens for sensitive npm actions ...