RSS
'Mini Shai-Hulud' supply chain attack targets SAP npm packages
Threat Research
Axios npm package compromised to deploy malware
NPM JavaScript packages abused to create scambait links in bulk
Naked Security
S3 Ep65: Supply chain conniption, NetUSB hole, Honda flashback, FTC muscle [Podcast + Transcript]
Node poisoning: hijacked package delivers coin miner and credential-stealing backdoor
Poisoned proxy PACs! The NPM package with a network-wide security hole…
Malicious npm package taken down after Microsoft warning