npm

  1. Software supply chain attacks move into developer tools

    Software supply chain attacks move into developer tools

    Developer tooling is now part of the attack surface Unit 42 says software supply chain attacks are moving deeper into the software development lifecycle, beyond finished application code. Its August 2026 research describes attackers targeting CI/CD pipelines, package ecosystems, developer...
  2. ChainDrop npm worm uses Ethereum routing to spread malware

    ChainDrop npm worm uses Ethereum routing to spread malware

    A supply chain worm targets developer trust Unit 42 says a self-propagating npm worm called ChainDrop infected more than 400 packages and reached software used at very large scale. The reported campaign is significant because it targets the systems developers rely on to build, test and publish...
  3. AI token jacking turns stolen API keys into gray market access

    AI token jacking turns stolen API keys into gray market access

    Stolen AI API Keys Become a Billing and Abuse Risk Unit 42 says cybercriminals are stealing developer API keys for AI platforms and using them to consume or resell model access. The security team describes the activity as token jacking, an AI-focused version of stealing access to paid computing...
  4. Supply chain compromise surge hits open source packages

    Supply chain compromise surge hits open source packages

    Open source packages move to the center of supply chain risk Google Threat Intelligence Group and Mandiant say large-scale open source software supply chain compromise expanded sharply across 2025 and early 2026. The report points to package repositories, developer tools and CI/CD workflows as...
Top