Back to Blog

Npm

4 articles on this topic.

Software Supply Chain22 August 2026

RedC2 4.0: Trojanized npm Packages Ship an AI-Steered Linux Backdoor

Fourteen npm packages posing as calendar and streak-tracking utilities were caught dropping RedC2 4.0, a commercial C2 framework whose new "Red Agent" layer lets operators issue plain-language commands instead of hand-crafting beacon syntax.

npmsoftware-supply-chainmalware
4 min readRead
Software Supply-Chain Security8 August 2026

npm's Keyv and Cacheable Hijacked in 'Mini Shai-Hulud' Supply-Chain Worm

A hijacked maintainer account let attackers trojan keyv, cacheable-request and flat-cache — reusing the same Shai-Hulud toolkit seen on PyPI and npm earlier in 2026.

supply-chain-securitynpmshai-hulud
4 min readRead
Software Supply Chain Security11 July 2026

Fake Paysafe, Skrill and Neteller SDKs on npm and PyPI Steal CI/CD Secrets

Seventeen packages impersonating payment-provider SDKs returned convincing fake success responses while quietly harvesting environment-variable secrets to an ngrok-tunnelled command-and-control server.

supply-chain-securitynpmpypi
4 min readRead
AI Security28 June 2026

Prompt Injection in the Wild: npm Malware Weaponises AI Content Filters to Evade Analysis

A malicious npm package published in June 2026 combines prompt injection, bio-weapons safety-trigger text, and context-flooding to blind AI-assisted dependency scanners — revealing a new evasion frontier in which the security toolchain itself becomes the attack surface.

prompt injectionsupply chainnpm
5 min readRead