< Back to situations

[ORGANIZATION]

Visual Studio Code

Featured in 1 tracked story · first seen

Situations

[ACTIVE] [TECHNOLOGY] [DE] [CN] [GB]

npm supply-chain malware attacks

2 clusters · 11 sources · last updated

Latest: ChainDrop npm Worm Infects Hundreds of Packages, Steals Credentials

In late July 2026, two beta versions of npm packages under the @joyfill namespace were found to contain a remote‑access trojan. The malicious code activates on import, retrieves encrypted payloads from multiple blockchai