Product

npm registry

Made by npm (GitHub). No known exploited vulnerabilities on record.

Coverage

Severity: HighAction: Be aware

Malicious npm Packages That Evade Defenses

This is an impressive piece of malware . Its sophistication says nation-state to me, but there is no direct evidence and certainly no attribution.

Severity: HighAction: Be aware

Shai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub Data

Threat actors stole the contents of 170 private repositories using an OAuth token stolen from a former employee's computer through the TanStack npm supply chain attack.