Researchers at Socket have uncovered a malicious npm package named nodejs-smtp, masquerading as the widely used nodemailer...
npm
The NPM ecosystem has been struck by a new supply chain attack, this time targeting the Nx...
Researchers have uncovered a new politically tinged campaign targeting the Solana blockchain ecosystem and, apparently, developers of...
Two malicious packages have been discovered in the NPM ecosystem, disguised as libraries for building bots and...
In the first half of 2025, Sonatype uncovered a large-scale, ongoing assault on the open-source software ecosystem,...
A malicious package discovered in the NPM ecosystem by researchers at Safety turned out to be far...
A major incident has rocked the npm ecosystem: the widely-used package eslint-config-prettier suddenly received an update devoid...
Hackers have successfully injected malicious code into popular npm packages by leveraging a phishing campaign against project...
A new threat has emerged in the realm of AI-assisted programming, known as “slopsquatting.” This attack has...
A new wave of malicious npm packages has been uncovered, linked to the ongoing Contagious Interview operation,...
GitHub issued an announcement that GitHub has completed the acquisition of npm. From the announcement of the...
Today, Microsoft bought npm for GitHub. Information about the acquisition was published by GitHub CEO Nat Friedman....