Developer Compromise 8
- Mini Shai-Hulud Spreads to Packagist: Malicious Intercom PHP Package Follows npm Compromise
- Malicious Checkmarx Artifacts Found in Official KICS Docker Repository and Code Extensions
- Namastex.ai npm Packages Hit with TeamPCP-Style CanisterWorm Malware
- CanisterWorm: npm Publisher Compromise Deploys Backdoor Across 29+ Packages
- GlassWorm Loader Hits Open VSX via Developer Account Compromise
- Shai Hulud Strikes Again (v2)
- Popular Tinycolor npm Package Compromised in Supply Chain Attack Affecting 40+ Packages
- npm 'is' Package Hijacked in Expanding Supply Chain Attack