SEOSiri Universal Developer UI Kit (@seosiri/developer-ui-kit)
www.npmjs.com/package/@seo...
#typescript #developers #seosiri @seosiri.com #npm

SEOSiri Universal Developer UI Kit (@seosiri/developer-ui-kit)
www.npmjs.com/package/@seo...
#typescript #developers #seosiri @seosiri.com #npm
Fake NebulaAI npm SDKs quietly install a Windows RAT that spies on your camera and mic. https://intel.threadlinqs.com/threat/TL-2026-3049 #ThreatIntel #KNTRAT #NebulaAI #npm
CVE-2026-1774 - ability
The @casl/ability library used in your applications can be tricked into granting actions it shouldn’t. This could let a malicious user perform operations they are not supposed to.…
Too many irrelevant or confusing CVEs? Use stackflag.com
Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm reconbee.com/tensorlake-n...
#tensorlake #npmpackage #npm #shaihulud #credential #cybersecurity #cyberattack
New npm malware MALFEX hides Overlord RAT and movinlike inside PNG-files targeting Windows devs. #SecurityNews #npm #MALFEX #SupplyChain #Malware #Windows https://thedailytechfeed.com/malfex-malware-npm-attack-hides-windows-threats-inside-png-files/
Checkmarx found eight malicious developer packages with 40,767 downloads—but that number says nothing about how many Windows PCs were infected.
The malware can steal saved p…
https://en.hacks.gr/i-checkmarx-entopise-okto-paketa-poy-mporoyn-na-molynoyn-ypologistes-me-windows/
Speaking of patch management, when the hell is someone gonna fix npm? FFS.
https://thehackernews.com/2026/10/eight-malicious-npm-packages-downloaded.html
CVE-2022-25860 - simple-git
The simple-git library used in several projects could let an attacker run their own code on your system. This risk has been fixed in newer releases, and the updates…
Too many irrelevant or confusing CVEs? Use stackflag.com
⏱ Caught early: npm @ikyyjee/[email protected] was on our radar 31 days before MAL-2026-17357 went public.
No install scripts? No problem—for attackers. Malicious npm packages sidestep a dependency security measure, turning trusted imports into a trap. jpmellojr.blogspot.com/2026/10/depe... #npm #Checkmarx #InstallScripts
No install scripts? No problem—for attackers. Malicious npm packages sidestep a dependency security measure, turning trusted imports into a trap. jpmellojr.blogspot.com/2026/10/depe... #npm #Checkmarx #InstallScripts
Eight malicious packages on npm were downloaded 40,767 times, researchers say.
Some could enable remote control or collect sensitive data.
That’s a measure of downloads—not a co…
https://en.hacks.gr/okto-kakovoyla-paketa-sto-npm-mporoysan-na-molynoyn-ypologistes-me-windows/
MALFEX uses npm packages (like function-flag, tldriver) to drop Overlord RAT and stealer on Windows via postinstall hooks. #Malware #npm #OverlordRAT #SupplyChain https://thedailytechfeed.com/eight-malicious-npm-packages-installed-over-40k-times-discovered-spreading-overlord-rat-stealer/
CVE-2026-104848 - tinypool
The tinypool library used to manage Node.js worker threads can be tricked into loading any script an attacker supplies. By adding malicious values to the default object…
Too many irrelevant or confusing CVEs? Use stackflag.com
CVE-2026-103922 - android
Both Android and iOS apps built with Capacitor can be tricked into loading any web page through an internal proxy path, making the page run with the app’s full privileges,…
Too many irrelevant or confusing CVEs? Use stackflag.com
TXTBOOK floods npm with fake T-Bank packages, then rebuilds Sliver from DNS TXT records. https://intel.threadlinqs.com/threat/TL-2026-2991 #ThreatIntel #Sliver #TXTBOOK #npm
CVE-2026-105850 - plugin-ecommerce
If you use Payload's e‑commerce plugin with Stripe and are running a version earlier than 3.90.0 (or a pre‑release before 4.0.0‑canary.34), the same order…
Too many irrelevant or confusing CVEs? Use stackflag.com
CVE-2026-105849 - payload
If you use the free Payload content system version 3.x before 3.90, a user who can only view documents could also read secret API keys stored in those documents. With…
Too many irrelevant or confusing CVEs? Use stackflag.com
CVE-2026-105845 - payload
Versions of the Payload content management system earlier than 3.88.0 (and certain early canary builds) let a user who can view data craft a request that inserts…
Too many irrelevant or confusing CVEs? Use stackflag.com