June 17 15 min read From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet A poisoned npm package infected 140+ projects with a hidden payload.
June 2 12 min read Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign A large-scale npm supply chain attack compromised over 90 versions of @redhat-cloud-services packages, silently infecting CI/CD environments and developer systems.
May 29 16 min read Malicious npm packages abuse dependency confusion to profile developer environments A dependency confusion campaign leveraged 33 malicious npm packages to collect reconnaissance data from developer and build environments.
May 28 9 min read Typosquatted npm packages used to steal cloud and CI/CD secrets The Mini Shai-Hulud campaign used malicious npm packages to target cloud and CI/CD credentials across developer environments.