Important notice for anyone maintaining a package on NPM. Certain NPM tokens have been invalidated in response to a supply chain attack. More information and Instructions on what to do if this has happened to your workflows can be found at https://github.com/orgs/community/discussions/196340 #npm #security
npm granular access token invalidation to prevent supply chain attacks · community · Discussion #196340

As initially announced on npm’s X channel, we have invalidated granular access tokens with write access that bypass two-factor authentication. This action was taken to help prevent supply chain att...

GitHub

We need a good NPM alternative. Trusted publishing isn't a good solution as it makes switching to FOSS alternatives harder.

#dev #webdev #javascript #npm #foss

314 npm packages just got compromised, 271 @antv, echarts-for-react, size-sensor, timeago.js (safedep.io)

https://safedep.io/mini-shai-hulud-strikes-again-314-npm-packages-compromised/

#npm #supplychain #attack #security

Mini Shai-Hulud Strikes Again: 317 npm Packages Compromised

A compromised npm maintainer account published 637 malicious versions across 317 packages including size-sensor, echarts-for-react, timeago.js, and hundreds of @antv scoped packages, affecting 15M+ monthly downloads.

SafeDep - Real-time Open Source Software Supply Chain Security

Copycat hits another npm package

A Shai-Hulud copycat worm has infected the npm package chalk-tempalte, appearing just five days after the original worm was open-sourced by its creators. The same threat actor also published three additional malicious npm packages containing infostealer code: @deadcode09284814/axios-util, axois-utils, and color-style-utils. These packages collectively received 2,678 weekly downloads and contain various malicious capabilities including credential theft, cryptocurrency wallet exfiltration, cloud configuration harvesting, and DDoS botnet functionality. The malware exfiltrates stolen data to remote command-and-control servers and uploads credentials to GitHub repositories. Researchers indicate the attacker operates from a home computer or local server farm and appears financially motivated, targeting victims' cryptocurrency assets while potentially offering DDoS-as-a-service capabilities.

Pulse ID: 6a0b921d3574a6ef2eca8d47
Pulse Link: https://otx.alienvault.com/pulse/6a0b921d3574a6ef2eca8d47
Pulse Author: AlienVault
Created: 2026-05-18 22:26:37

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#Cloud #CyberSecurity #DDoS #DoS #GitHub #InfoSec #InfoStealer #Malware #NPM #OTX #OpenThreatExchange #RAT #RCE #Worm #bot #botnet #cryptocurrency #iOS #AlienVault

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange

Active Supply Chain Attack Compromises Packages on npm

An active npm supply chain attack has compromised packages in the @antv ecosystem, affecting the maintainer account 'atool'. The attack is part of the Mini Shai-Hulud campaign, involving 639 compromised package versions across 323 unique packages. Notable affected packages include echarts-for-react with 1.1 million weekly downloads, and widely-used @antv packages for data visualization. The malware uses obfuscated install-time payloads that harvest developer credentials, GitHub tokens, npm tokens, AWS credentials, and other secrets from development and CI/CD environments. Stolen data is encrypted with AES-256-GCM and exfiltrated to a command-and-control server, with GitHub repositories used as fallback channels. The malware contains worm-like functionality to republish compromised packages and propagate through the npm ecosystem.

Pulse ID: 6a0c1b289f4fe8b7bdf00a84
Pulse Link: https://otx.alienvault.com/pulse/6a0c1b289f4fe8b7bdf00a84
Pulse Author: AlienVault
Created: 2026-05-19 08:11:20

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#AWS #CyberSecurity #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #SupplyChain #Worm #bot #AlienVault

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange

Minko Gechev (@mgechev)

skillgrade v0.1.5가 공개되었습니다. OpenCode 지원이 추가됐고, grader provider를 설정 가능하게 했으며, 전반적인 오류 처리와 안정성이 개선되었습니다. 로컬 provider 관련 버그도 수정되어 AI 모델/에이전트 평가 도구로서의 사용성이 좋아졌습니다.

https://x.com/mgechev/status/2056527291493351792

#opensource #aiops #evaluation #npm

Minko Gechev (@mgechev) on X

Just published skillgrade v0.1.5! 🚀 • Added support for the OpenCode • Configurable grader provider support • Improved overall error handling & stability • Fixes for the local provider npm i -g skillgrade https://t.co/NPVCKSG7CI

X (formerly Twitter)
Wrote a tiny #Python script to scan for #npm hooks in package.json files (scans dir tree recursively): https://github.com/panzi/hookscan Does #pip also have such hooks? Might add scanning for those in the future. Not now. #NodeJS #JavaScript
GitHub - panzi/hookscan: Scan for hooks in `package.json` files.

Scan for hooks in `package.json` files. Contribute to panzi/hookscan development by creating an account on GitHub.

GitHub

Malware Campaign Compromises Hundreds of npm Packages

A new, highly aggressive malware campaign, linked to the notorious TeamPCP group, has infected hundreds of npm packages, putting countless environments at risk of exposure. If you're concerned about potential damage, take immediate action to rotate secrets, remove persistence artifacts, and review recent publish activity.

https://osintsights.com/malware-campaign-compromises-hundreds-of-npm-packages?utm_source=mastodon&utm_medium=social

#MalwareOperations #Npm #Teampcp #MiniShaihulud #SupplyChain

Malware Campaign Compromises Hundreds of npm Packages

Protect your environment from TeamPCP's Mini Shai‑Hulud malware campaign compromising hundreds of npm packages - learn how to secure your system now and prevent further attacks.

OSINTSights

And no, making programmers jump through hoops to publish their code isn't a solution either.

When I ended my brief stint maintaining an #npm package, they were cranking up the authentication requirements already. By now, they probably require a verification can and a stool sample every time you want to publish.

This has done ABSOLUTELY NOTHING to prevent supply chain attacks. Maintainers are still getting phished. Because they've no time for vigilance.

#security #cybersecurity #infosec

Leaked Shai-Hulud malware fuels new npm infostealer campaign

The Shai-Hulud malware leaked last week is now used in new attacks on the Node Package Manager (npm) index, as infected packages emerged over the weekend.

BleepingComputer