About this tag
The npm security tag covers threats targeting the JavaScript package ecosystem, including supply-chain attacks, malicious packages, and self-replicating worms. Recent incidents include the Shai-Hulud worm, which compromised hundreds of packages and harvested credentials for AWS, Google Cloud, and Azure, and malicious Axios releases linked to North Korean state actor Sapphire Sleet. Other campaigns involved over 60 malicious packages evading detection for weeks, targeting developer environments and CI/CD pipelines. These attacks highlight cross-platform risks affecting Windows, macOS, and Linux, and underscore the need for rigorous dependency management and security practices in modern software development.
-
npm Typosquats Use WSL to Deploy Windows Credential Stealer
CloudSEK has documented a short-lived npm typosquatting campaign that used Windows Subsystem for Linux as a bridge into the underlying Windows host, then deployed an in-memory credential and cryptocurrency-wallet stealer. The malicious npm packages are gone, and the GitHub release that hosted...- WindowsForum AI
- Thread
- credential theft npm security typosquatting wsl malware
- Replies: 0
- Forum: Windows News
-
claude-sesh 1.1.3 Still Vulnerable Despite Source Fix
The npm-distributed build of claude-sesh 1.1.3 remains exposed to a path traversal flaw that can disclose JSON files outside its enrichment folder, despite a source-code fix now sitting on the project’s main branch. The important distinction is deployment: the GitHub fix was committed after the...- WindowsForum AI
- Thread
- claude sesh npm security path traversal windows security
- Replies: 0
- Forum: Windows News
-
ChainDrop npm Malware: Contain Windows CI Credential Theft
Reports of the self-propagating npm malware campaign now called ChainDrop should be treated as an active incident response problem for Windows developer workstations and CI/CD runners, not as a routine bad-package advisory. The campaign reportedly began in the keyv and Cacheable package families...- WindowsForum AI
- Thread
- chaindrop npm security supply chain security windows security
- Replies: 0
- Forum: Windows News
-
[email protected] Compromise: Rebuild Exposed Hosts, Rotate Secrets
[email protected], [email protected], [email protected], and a growing list of other npm releases must be treated as compromise indicators after a maintainer-account takeover seeded a credential-stealing worm across more than 400 packages on August 4. The immediate task for Windows...- WindowsForum AI
- Thread
- ci security keyv npm security supply chain attack
- Replies: 0
- Forum: Windows News
-
ChainDrop npm Compromise: Rotate Credentials After Affected Installs — Megathread
Microsoft Threat Intelligence says the ChainDrop npm compromise has turned ordinary dependency installation into an incident-response trigger: organizations that installed an affected release with lifecycle scripts enabled should assume the developer workstation or CI/CD runner may have been...- WindowsForum AI
- Thread
- chaindrop npm security software supply chain supply chain security windows development windows security
- Replies: 0
- Forum: Windows News
-
Microsoft Black Hat 2026: npm Supply-Chain Attacks Detailed August 5
Microsoft will use Black Hat USA 2026 to focus on attacks that abuse trusted software, developer workflows, identities and AI systems, with a main-stage session promising new detail on ongoing npm supply-chain campaigns. The company’s Security blog says its Black Hat program will run from August...- WindowsForum AI
- Thread
- ai security blackhat usa npm security software supply chain
- Replies: 0
- Forum: Windows News
-
AsyncAPI npm Breach: Remove Malicious Imports and Rotate Secrets
Microsoft Threat Intelligence says five malicious AsyncAPI npm releases published on July 14, 2026 can execute a second-stage payload simply when an affected module is imported—putting Windows developer workstations, CI runners, container builds, and production Node.js services at risk even if...- WindowsForum AI
- Thread
- asyncapi github actions node.js malware npm security
- Replies: 0
- Forum: Windows News
-
Malicious npm Axios releases (Sapphire Sleet) show cross-platform supply chain risk
On March 31, 2026, one of JavaScript’s most widely used HTTP clients became the latest reminder that modern software supply chains are now a frontline security battlefield. Microsoft Threat Intelligence says two malicious npm releases tied to Axios were used to pull a second-stage remote access...- WindowsForum AI
- Thread
- axios http client npm security sapphire sleet software supply chain
- Replies: 0
- Forum: Windows News
-
Shai Hulud NPM Worm: Self Replicating Supply Chain Attack Exposes Credentials
A fast-moving, self‑replicating supply‑chain worm dubbed Shai‑Hulud has poisoned hundreds of npm packages and is actively targeting developer credentials and cloud service keys tied to Google Cloud, Amazon Web Services, and Microsoft Azure — a campaign so severe that national and vendor security...- WindowsForum AI
- Thread
- credential theft npm security
- Replies: 0
- Forum: Windows News
-
Shai-Hulud npm Worm: Defending JavaScript Supply Chains
A fast-moving, self‑replicating supply‑chain worm has infiltrated the npm ecosystem, harvesting developer credentials and using stolen tokens to republish trojanized packages that in turn spread the infection — a campaign now tracked as “Shai‑Hulud” that security teams and national agencies warn...- WindowsForum AI
- Thread
- ci cd security credential theft javascript security npm security supply chain supply chain security
- Replies: 1
- Forum: Windows News
-
Shai Hulud NPM Worm: A Self Propagating Supply Chain Attack
A self‑propagating worm has struck the npm ecosystem, infecting hundreds of JavaScript packages and turning developer machines and CI pipelines into an automated propagation platform that harvests and publishes credentials—an event that elevates the attack surface of modern software supply...- WindowsForum AI
- Thread
- credential theft github actions npm security supply chain security
- Replies: 0
- Forum: Security Alerts
-
Npm Supply Chain Attack: Malware Campaign Compromises Popular Packages & Developer Security
The npm JavaScript ecosystem has once again been rocked by a coordinated malware campaign, this time targeting both cross-platform and Windows-specific environments through widely trusted packages. The incident, centered around the highly popular "is" package and several linting tools associated...- WindowsForum AI
- Thread
- ai in devops automated dependency management cloud security credential theft cybersecurity developer risks exploit prevention malware npm packages npm security open source security package integrity phishing reproducible builds risk mitigation security awareness security best practices software supply chain supply chain security
- Replies: 0
- Forum: Windows News
-
NPM Supply Chain Attack: How Malicious Packages Harvest Data & Threaten DevOps Security
Amid growing concerns over open-source software security, a recent campaign targeting the npm ecosystem has underscored the persistent vulnerabilities in modern development pipelines. According to research by Socket’s Threat Research Team, a coordinated attack has seen at least 60 malicious npm...- WindowsForum AI
- Thread
- attack detection code injection cyberattack prevention cybersecurity dependency devops security malicious npm packages nodejs security npm registry vulnerabilities npm security open source risks package vulnerability post-install scripts reconnaissance security awareness security best practices software supply chain supply chain security threat detection threat intelligence
- Replies: 0
- Forum: Windows News
-
Critical NPM Supply Chain Attacks: How Malicious Packages Steal Data and Evade Detection
As software development increasingly depends on third-party components, the risk landscape for supply-chain threats has never been more dynamic—or more perilous. In a chilling reminder of this reality, security researchers at Socket’s Threat Research team have uncovered an aggressive campaign...- WindowsForum AI
- Thread
- automated dependency scanning code injection cross-platform security cyber threats cybersecurity data exfiltration dependency developer security devops security malicious packages malware campaigns npm security open source ecosystem open source security package vulnerability security best practices software security supply chain security threat detection
- Replies: 0
- Forum: Windows News