Npm is a topic tracked in our intelligence system with 5 linked articles.
A data-rich look at human-in-the-loop AI permissions showing that humans miss roughly one-third of threats in a 40k-run game, with exfiltration/credential risks and end-of-session fatigue highlighting the need for stronger sandboxing and credential controls.
Malicious npm packages target Alibaba tool users with a cross-platform RAT via a targeted software supply chain attack; one package, lib-mtop, mirrors an Alibaba package name.
NullReceiver hides the C2 IP inside a fabricated Ethereum transfer address in two trojanized npm packages, illustrating a blockchain-based dead-drop C2 evolution.
A credential-stealing npm worm linked to Keyv infected hundreds of packages; SafeDep found 353 poisoned versions across 79 package names, with a wider footprint of 442 versions across 353 names, and Aikido estimates at least 868 affected packages.
Two compromised joyfill npm packages execute a RAT on import, highlighting software supply-chain risk in Node.js ecosystems.
A tiny schema-first TS/JS library that emits standard JSON Schema, supports TS inference, fast O(1) validation via prime-jump, and OpenAI-ready outputs, with an accompanying npm token policy update.
Subscribe for real-time topic updates and unlimited access to our intelligence platform.