Recently, security researchers Socket found 10 packages on npm targeting software developers, specifically those who use the ...
A critical vulnerability in the popular expr-eval JavaScript library, with over 800,000 weekly downloads on NPM, can be ...
Having another security threat emanating from Node.js’ Node Package Manager (NPM) feels like a weekly event at this point, ...
Attackers are exploiting a major weakness that has allowed them access to the NPM code repository with more than 100 credential-stealing packages since August, mostly without detection.
Ten malicious packages mimicking legitimate software projects in the npm registry download an information-stealing component ...
The ongoing ‘PhantomRaven’ malicious campaign has infected 126 npm packages to date, representing 86,000 downloads ...
Supply chain security company Safety has discovered a trojan in NPM that masqueraded as Anthropic’s popular Claude Code AI ...
Software supply chain security firm JFrog has disclosed the details of a critical vulnerability affecting a popular React ...
The Backend-for-Frontend pattern addresses security issues in Single-Page Applications by moving token management back to the ...
A massively popular JavaScript library (npm package) was hacked today and modified with malicious code that downloaded and installed a password stealer and cryptocurrency miner on systems where the ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results