< Back to situations

[ORGANIZATION]

Node.js

Featured in 5 tracked stories · first seen

Situations

[ACTIVE] [TECHNOLOGY] [DE] [CN] [GB]

npm supply-chain malware attacks

2 clusters · 11 sources · last updated

Latest: ChainDrop npm Worm Infects Hundreds of Packages, Steals Credentials

In late July 2026, two beta versions of npm packages under the @joyfill namespace were found to contain a remote‑access trojan. The malicious code activates on import, retrieves encrypted payloads from multiple blockchai

[ACTIVE] [TECHNOLOGY]

JavaScript framework security patches

2 clusters · 4 sources · last updated

Latest: Node.js releases emergency security update fixing 11 vulnerabilities

In mid‑July 2026 the maintainers of the Next.js web‑framework announced a new monthly security release program. The first update, scheduled for July 20, will patch nine vulnerabilities (four high‑severity and five medium

Also covered in