70% of new NPM packages in last 6 months were spam

npm Packages Found Sending Malware in JPEG files

Unintended Consequences of Open Source Sustainability Platforms

Ongoing malware laced developer job interviews

Crypto-Themed NPM Packages Found Delivering Stealthy Malware

Rust Malware Staged on Crates.io

Malicious NPM packages attributed to North Korean state actors

Mischievous NPM Publications

How Attackers Can Sneakily Slip Malware Packages Into Poetry.lock Files

Attackers Repurposing existing Python-based Malware for Distribution on NPM

Malicious Actors Use Unicode Support in Python to Evade Detection

Attackers are hiding malware in minified packages distributed to NPM

A PyPI typosquatting campaign post-mortem

Aggressive Attack on PyPI Attempting to Deliver Rust Executable

Ransomware being published to PyPI in ongoing campaign

Malicious Python Packages Replace Crypto Addresses in Developer Clipboards

Dozens of malicious PyPI packages discovered targeting developers

Disrupting an attacker publishing malware to PyPI

Active Typosquatting Campaign Targeting NPM Developers

The Anatomy of a Malicious Package

Using Entropy to Identify Obfuscated Malicious Code

Using Spark and Rust build distributed and flexible analytics pipelines

An analysis of author behavior during Hacktoberfest 2020

How NPM Malware Works

The Anatomy of a Malicious Package