MikeTrendsTrends right now

search

npm

Trends

  1. 1
    PyPI package MemoryOS accused of hiding credential stealer●"import memos" alone is enough to start a credential stealer. MemoryOS 2.0.34 on PyPI: 149 modules call get_logger() atMmastodonTechnologyCybersecurity12 d ago

    Security researchers report that the Python package MemoryOS, version 2.0.34 on PyPI, is trojanized: simply importing the 'memos' module is said to trigger malicious code. Of the package's modules, 149 reportedly call get_logger() at import time, and a modified logger allegedly launches a Go binary, 'sckit', that harvests .npmrc files, Vault tokens, SSH keys and environment secrets. The npm OpenClaw plugin is also named in the report.

  2. 2
    85 malicious npm packages found in typosquatting campaign▼(cloudsek.com) Automated Typosquatting Attack on npm Registry: 85 Malicious Packages Target Popular Libraries via ScopedMmastodonTechnologyCybersecurity17 h ago

    Cybersecurity firm CloudSEK reports an automated typosquatting campaign on the npm registry, with 85 malicious packages published under the @prime0 scope to impersonate popular libraries and trick developers into installing them. The packages target widely used open-source dependencies, raising concerns about supply chain security and the ease of automating fake package publication at scale.

  3. 3
    DirtyBlanket Linux Worm Spreads Through Malicious npm Packages●(safedep.io) DirtyBlanket: Self-Spreading Linux Worm Distributed via Malicious npm Packages Targeting Developers In brieMmastodonTechnologyCybersecurity18 h ago

    Security researchers at SafeDep report a self-spreading Linux worm, dubbed DirtyBlanket, distributed through nine malicious npm packages impersonating popular libraries such as Express and React. Once installed, the malware targets developers' Linux machines and propagates further, making supply-chain attacks on the JavaScript ecosystem a renewed concern for developers reviewing dependencies.

  4. 4
    101 Malicious npm Packages Enroll Developers in WhatsApp Groups●101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent✉newsTechnologySoftware9 min ago

    Security researchers have identified 101 malicious packages on the npm registry that secretly add developers' WhatsApp accounts to groups without their consent. The campaign targets software developers who install compromised dependencies, raising concerns about supply chain attacks spreading through the widely used JavaScript package ecosystem and unwanted contact via WhatsApp.

Repos