Huit paquets malveillants #npm, téléchargés 40 767 fois, diffusent un RAT Overlord et des voleurs d’infos. Campagne MALFEX attribuée à un acteur isolé depuis août 2023. ⚠️🔐 #cybersécurité #malware

Huit paquets malveillants #npm, téléchargés 40 767 fois, diffusent un RAT Overlord et des voleurs d’infos. Campagne MALFEX attribuée à un acteur isolé depuis août 2023. ⚠️🔐 #cybersécurité #malware
Shai-Hulud's npm worm persists via .claude + VS Code configs, with a token-revoke dead-man's switch. https://intel.threadlinqs.com/threat/TL-2026-3216 #ThreatIntel #ShaiHulud #Mini #npm
CVE-2026-108261 - tinacms
The TinaCMS admin interface builds the preview frame URL from the page’s hash without confirming it points to the same site. An attacker can craft a link that makes the admin load an…
Too many irrelevant or confusing CVEs? Use stackflag.com
Abandoned is a range, not a number. Our Q3 report measures it. Free: valuechainrisk.org/q3 #opensource #npm
CVE-2019-19919 - handlebars.js
Old versions of Handlebars, a template engine used in web development, can be exploited by hackers to execute malicious code on a server. This can happen if an attacker sends…
Too many irrelevant or confusing CVEs? Use stackflag.com
CVE-2026-105851 - payload
Versions of the Payload headless CMS before 3.90.0 (and certain canary builds) let users duplicate a document and unintentionally copy data from fields that should be…
Too many irrelevant or confusing CVEs? Use stackflag.com
The 'tensorlake' NPM package was compromised with a self-propagating worm, Shai-Hulud. Version 0.5.144 steals developer credentials (AWS, K8s, SSH keys) and spreads to other packages. C2 uses an Ethereum contract. #SupplyChain #NPM #malware
🌐 cyber[.]netsecops[.]io
⏱ Caught early: npm @xayz/[email protected] was on our radar 53 days before MAL-2026-17384 went public.
"Evolution of Web3 in Cloud Supply Chain Attacks" published by PaloaltoNetworks. #NPM, #AlluringPisces, #EtherHiding, #PolinRider, #NullReceiver https://unit42.paloaltonetworks.com/web3-cloud-supply-chain-attacks
CVE-2026-107722 - fast-jwt
The fast-jwt library (versions 6.2.0 and later) still fails to strip certain non‑space characters before checking a public key format. As a result, an attacker who can add a…
Too many irrelevant or confusing CVEs? Use stackflag.com
ChainDrop infected 400+ npm packages, according to researchers.
Using Ethereum as a changeable address book let attackers redirect stolen da…
SEOSiri Universal Developer UI Kit (@seosiri/developer-ui-kit)
www.npmjs.com/package/@seo...
#typescript #developers #seosiri @seosiri.com #npm
Fake NebulaAI npm SDKs quietly install a Windows RAT that spies on your camera and mic. https://intel.threadlinqs.com/threat/TL-2026-3049 #ThreatIntel #KNTRAT #NebulaAI #npm
CVE-2026-1774 - ability
The @casl/ability library used in your applications can be tricked into granting actions it shouldn’t. This could let a malicious user perform operations they are not supposed to.…
Too many irrelevant or confusing CVEs? Use stackflag.com
Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm reconbee.com/tensorlake-n...
#tensorlake #npmpackage #npm #shaihulud #credential #cybersecurity #cyberattack
New npm malware MALFEX hides Overlord RAT and movinlike inside PNG-files targeting Windows devs. #SecurityNews #npm #MALFEX #SupplyChain #Malware #Windows https://thedailytechfeed.com/malfex-malware-npm-attack-hides-windows-threats-inside-png-files/
Checkmarx found eight malicious developer packages with 40,767 downloads—but that number says nothing about how many Windows PCs were infected.
The malware can steal saved p…
https://en.hacks.gr/i-checkmarx-entopise-okto-paketa-poy-mporoyn-na-molynoyn-ypologistes-me-windows/
Speaking of patch management, when the hell is someone gonna fix npm? FFS.
https://thehackernews.com/2026/10/eight-malicious-npm-packages-downloaded.html