News

Dozens of npm libraries, including a color library with over 2 million downloads a week, have been replaced with novel ...
Qix is an open source maintainer account that was compromised by a phishing attack. This allowed attackers to infect 18 popular npm packages with malicious code. Together, these packages are ...
Intrusions bear the same hallmarks as recent Nx mess The npm platform is the target of another supply chain attack, with ...
Hackers injected malicious code into nearly a dozen 20 NPM packages with billions of weekly downloads in a software supply chain attack after phishing a maintainer’s account.