Tagged: NPM Malware

SANDWORM_MODE worm attack diagram illustrating AI toolchain supply chain compromise 0

SANDWORM_MODE Worm Exploits AI Toolchains and Supply Chains

The Emergence of AI Infrastructure Worms Malicious packages have evolved to inconspicuously masquerade as routine operations executed by artificial intelligence assistants and automated build systems. The pervasive SANDWORM_MODE worm systematically exfiltrates cryptographic keys, infects...

PolinRider North Korea supply chain attack targeting npm, Go modules, and Chrome extensions 0

PolinRider Supply Chain Attack Spans npm, Go, Chrome

PolinRider is no longer a story about a handful of malicious npm packages. Researchers at Socket uncovered 162 malicious release artifacts spread across 108 packages and browser extensions. The campaign now reaches multiple open-source...

Miasma supply chain attack, GitHub malware toolkit, software supply chain security, npm package malware 0

Miasma Toolkit Targets Software Supply Chains

When a new batch of source code appeared on GitHub, it unexpectedly caught the attention of security researchers. Over the past few days, repositories bearing the name Miasma-Open-Source-Release began appearing across the platform in...