Ten typosquatted npm packages (Jul 4, 2025) delivered a 24MB PyInstaller info stealer using 4 obfuscation layers; ~9,900 ...
Supply chain security company Safety has discovered a trojan in NPM that masqueraded as Anthropic’s popular Claude Code AI ...
Ten malicious packages mimicking legitimate software projects in the npm registry download an information-stealing component ...
Attackers are exploiting a major weakness that has allowed them access to the NPM code repository with more than 100 credential-stealing packages since August, mostly without detection.
An advanced malware campaign on the npm registry steals the very keys that control enterprise cloud infrastructure.
A little bit about Node.js, it is a beautifully written cross-platform open-source JavaScript runtime environment built on Google’s Chrome’s V8 JavaScript engine. Node.js basically lets you code ...
GitHub, part of Microsoft, announced on Monday that it's agreed to acquire open source JavaScript solutions company npm Inc. Financial terms of the deal weren't described. Nat Friedman, GitHub's CEO, ...
Results that may be inaccessible to you are currently showing.
Hide inaccessible results