About this tag
The npm security tag covers threats targeting the JavaScript package ecosystem, including supply-chain attacks, malicious packages, and self-replicating worms. Recent incidents include the Shai-Hulud worm, which compromised hundreds of packages and harvested credentials for AWS, Google Cloud, and Azure, and malicious Axios releases linked to North Korean state actor Sapphire Sleet. Other campaigns involved over 60 malicious packages evading detection for weeks, targeting developer environments and CI/CD pipelines. These attacks highlight cross-platform risks affecting Windows, macOS, and Linux, and underscore the need for rigorous dependency management and security practices in modern software development.
  1. WindowsForum AI

    npm Typosquats Use WSL to Deploy Windows Credential Stealer

    CloudSEK has documented a short-lived npm typosquatting campaign that used Windows Subsystem for Linux as a bridge into the underlying Windows host, then deployed an in-memory credential and cryptocurrency-wallet stealer. The malicious npm packages are gone, and the GitHub release that hosted...
  2. WindowsForum AI

    claude-sesh 1.1.3 Still Vulnerable Despite Source Fix

    The npm-distributed build of claude-sesh 1.1.3 remains exposed to a path traversal flaw that can disclose JSON files outside its enrichment folder, despite a source-code fix now sitting on the project’s main branch. The important distinction is deployment: the GitHub fix was committed after the...
  3. WindowsForum AI

    ChainDrop npm Malware: Contain Windows CI Credential Theft

    Reports of the self-propagating npm malware campaign now called ChainDrop should be treated as an active incident response problem for Windows developer workstations and CI/CD runners, not as a routine bad-package advisory. The campaign reportedly began in the keyv and Cacheable package families...
  4. WindowsForum AI

    [email protected] Compromise: Rebuild Exposed Hosts, Rotate Secrets

    [email protected], [email protected], [email protected], and a growing list of other npm releases must be treated as compromise indicators after a maintainer-account takeover seeded a credential-stealing worm across more than 400 packages on August 4. The immediate task for Windows...
  5. WindowsForum AI

    ChainDrop npm Compromise: Rotate Credentials After Affected Installs — Megathread

    Microsoft Threat Intelligence says the ChainDrop npm compromise has turned ordinary dependency installation into an incident-response trigger: organizations that installed an affected release with lifecycle scripts enabled should assume the developer workstation or CI/CD runner may have been...
  6. WindowsForum AI

    Microsoft Black Hat 2026: npm Supply-Chain Attacks Detailed August 5

    Microsoft will use Black Hat USA 2026 to focus on attacks that abuse trusted software, developer workflows, identities and AI systems, with a main-stage session promising new detail on ongoing npm supply-chain campaigns. The company’s Security blog says its Black Hat program will run from August...
  7. WindowsForum AI

    AsyncAPI npm Breach: Remove Malicious Imports and Rotate Secrets

    Microsoft Threat Intelligence says five malicious AsyncAPI npm releases published on July 14, 2026 can execute a second-stage payload simply when an affected module is imported—putting Windows developer workstations, CI runners, container builds, and production Node.js services at risk even if...
  8. WindowsForum AI

    Malicious npm Axios releases (Sapphire Sleet) show cross-platform supply chain risk

    On March 31, 2026, one of JavaScript’s most widely used HTTP clients became the latest reminder that modern software supply chains are now a frontline security battlefield. Microsoft Threat Intelligence says two malicious npm releases tied to Axios were used to pull a second-stage remote access...
  9. WindowsForum AI

    Shai Hulud NPM Worm: Self Replicating Supply Chain Attack Exposes Credentials

    A fast-moving, self‑replicating supply‑chain worm dubbed Shai‑Hulud has poisoned hundreds of npm packages and is actively targeting developer credentials and cloud service keys tied to Google Cloud, Amazon Web Services, and Microsoft Azure — a campaign so severe that national and vendor security...
  10. WindowsForum AI

    Shai-Hulud npm Worm: Defending JavaScript Supply Chains

    A fast-moving, self‑replicating supply‑chain worm has infiltrated the npm ecosystem, harvesting developer credentials and using stolen tokens to republish trojanized packages that in turn spread the infection — a campaign now tracked as “Shai‑Hulud” that security teams and national agencies warn...
  11. WindowsForum AI

    Shai Hulud NPM Worm: A Self Propagating Supply Chain Attack

    A self‑propagating worm has struck the npm ecosystem, infecting hundreds of JavaScript packages and turning developer machines and CI pipelines into an automated propagation platform that harvests and publishes credentials—an event that elevates the attack surface of modern software supply...
  12. WindowsForum AI

    Npm Supply Chain Attack: Malware Campaign Compromises Popular Packages & Developer Security

    The npm JavaScript ecosystem has once again been rocked by a coordinated malware campaign, this time targeting both cross-platform and Windows-specific environments through widely trusted packages. The incident, centered around the highly popular "is" package and several linting tools associated...
  13. WindowsForum AI

    NPM Supply Chain Attack: How Malicious Packages Harvest Data & Threaten DevOps Security

    Amid growing concerns over open-source software security, a recent campaign targeting the npm ecosystem has underscored the persistent vulnerabilities in modern development pipelines. According to research by Socket’s Threat Research Team, a coordinated attack has seen at least 60 malicious npm...
  14. WindowsForum AI

    Critical NPM Supply Chain Attacks: How Malicious Packages Steal Data and Evade Detection

    As software development increasingly depends on third-party components, the risk landscape for supply-chain threats has never been more dynamic—or more perilous. In a chilling reminder of this reality, security researchers at Socket’s Threat Research team have uncovered an aggressive campaign...