Fake VS Code Extension on NPM Spreads Multi-Stage Malware

Malicious Code Deletes Directories If You Do Not Have a License

Foiled npm typosquatting attack targeted packages with cumulative 1.5bn weekly downloads

Cloud-Native Applications and Managing Their Dependencies

Attacker floods npm with crypto-mining packages that mine Monero when installed with the default configuration

Single Author Uploaded 168 Packages to npm as Part of a Massive Dependency Confusion Attack

A Weaponized npm Package '@core-pas/cyb-core' Proclaimed Pentesting Related