[ORGANIZATION]
npm
Featured in 10 tracked stories · first seen
Situations
North Korean crypto hacking and software supply-chain ops
8 clusters · 32 sources · last updated
Latest: North Korea expands fraudulent job schemes into healthcare and sales
By August 2026, North Korean state-sponsored actors had targeted over 1,640 organizations across 57 countries. Intelligence from Proofpoint identified the ‘UNK_DeadDrop’ cluster, which targets developers via phishing cam
npm supply-chain malware attacks
3 clusters · 16 sources · last updated
Latest: ChainDrop worm compromises hundreds of npm packages
In late July 2026, two beta versions of npm packages under the @joyfill namespace were found to contain a remote‑access trojan. The malicious code activates on import, retrieves encrypted payloads from multiple blockchai
Also covered in
-
Malicious npm packages deliver RedC2 Linux backdoor
[TECHNOLOGY] · 2 sources ·
-
npm 12 disables postinstall scripts by default to enhance security
[TECHNOLOGY] · 2 sources ·
-
Deno improves npm security via sandboxed architecture
[TECHNOLOGY] · 2 sources ·
-
GitHub introduces 3‑day Dependabot cooldown to curb supply‑chain attacks
[TECHNOLOGY] · 3 sources ·
-
East Asian Hackers Deploy New Malware Against Middle East Governments and Alibaba Developers
[TECHNOLOGY] · 2 sources ·