Skip to content
Threat Digest
Explainers Data Breaches Vulnerabilities & CVEs Ransomware & Malware
Nation-State Threats Security Tools Compliance & Policy Cloud Security Threat Intelligence

#npm

Illustration of a stylized worm or sandworm tunneling through code packages.
Vulnerabilities & CVEs

170+ Packages Wormed: TeamPCP's Mini Shai-Hulud Campaign Explained

A sophisticated, self-propagating worm has silently infected over 170 open-source packages, marking a disturbing new escalation in supply chain attacks. This isn't just a breach; it's a breach of trust, and the implications are staggering.

6 min read 2 days, 3 hours ago
A screenshot of the VS Code editor with a warning symbol overlayed on the Nx Console extension icon.
Vulnerabilities & CVEs

Nx Console Hijacked: VS Code Developers Targeted

They say developers are paranoid. Turns out, they're right. A popular VS Code extension, Nx Console, just became the latest vector for a sophisticated credential stealer.

5 min read 4 days, 10 hours ago
Illustration of a computer screen displaying code with a menacing digital entity emerging from it.
Ransomware & Malware

npm Under Siege: Shai-Hulud's Unchecked Spread

A leaked malware strain is now fueling a fresh wave of attacks against the Node Package Manager. Developers' secrets and systems are increasingly at risk.

6 min read 5 days, 1 hour ago
Abstract digital art representing code and network connections, with a red warning overlay.
Ransomware & Malware

npm Packages Pack Infostealers & DDoS Bots [Alert]

The open-source code for malware is becoming a dangerous playground for attackers. Researchers just found four new npm packages peddling everything from data-stealing worms to potent DDoS bots.

5 min read 5 days, 9 hours ago
Abstract depiction of computer code with a lock icon overlayed.
Vulnerabilities & CVEs

node-ipc Compromised: Your Secrets Are Now Dinner

The npm ecosystem just took another hit. The widely used node-ipc package has been compromised, actively stealing sensitive developer credentials.

4 min read 1 week, 1 day ago
Abstract representation of a tangled web of code, with red nodes indicating security breaches and interconnected lines showing propagation.
Vulnerabilities & CVEs

npm's 'Nuisance' Era is Over: The Rise of Wormable Attacks

The days of worrying about minor npm annoyances are long gone. A chilling new breed of self-replicating malware is reshaping the threat landscape, turning the developer's trusted toolkit into a weapon.

6 min read 4 weeks ago

Categories

Explainers Data Breaches Vulnerabilities & CVEs Ransomware & Malware Nation-State Threats Security Tools Compliance & Policy Cloud Security
Threat Digest

Threat intelligence. Zero noise.

More

  • RSS Feed
  • Sitemap
  • About
  • Editorial Process
  • Advertise

Legal

  • Privacy
  • Terms
  • Work With Us

Our Network

The AI Catchup AI & Machine Learning Threat Digest Cybersecurity Legal AI Beat Legal Tech Fintech Rundown Finance & Banking DevTools Feed Developer Tools Open Source Beat Open Source Fintech Dose Crypto & DeFi Chip Beat Semiconductors AdTech Beat Ad Technology Supply Chain Beat Logistics

© 2026 Threat Digest. All rights reserved.

🏠Home 🔍Search 🔖Saved 📂Categories
Privacy & cookies

We use a privacy-respecting analytics tool to count page views — no personal profiles, no ad tracking, no third-party cookies. Accept to help us understand which stories matter to readers.

Details