home.social

#npmpackages — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #npmpackages, aggregated by home.social.

  1. Malware Worms Red Hat npm Packages, Targets Cloud Credentials

    A single compromised Red Hat employee's GitHub account was used to seed dozens of Red Hat npm package releases with a self-propagating credential-stealer, putting cloud credentials at risk. The malicious packages, downloaded around 80,000 times a week, are still considered a live threat.

    osintsights.com/malware-worms-

    #MalwareOperations #SupplyChain #CloudCredentials #NpmPackages #RedHat

  2. #Supplychainattacks targeting security and developer tools continue, with #SAP, #Intercom, and #lightning #npmpackages compromised. The attacks, attributed to TeamPCP, involve credential-stealing malware that self-propagates, encrypts stolen data, and exfiltrates it to a new GitHub repository. theregister.com/2026/04/30/sup #tech #media #news

  3. #Supplychainattacks targeting security and developer tools continue, with #SAP, #Intercom, and #lightning #npmpackages compromised. The attacks, attributed to TeamPCP, involve credential-stealing malware that self-propagates, encrypts stolen data, and exfiltrates it to a new GitHub repository. theregister.com/2026/04/30/sup #tech #media #news

  4. #Supplychainattacks targeting security and developer tools continue, with #SAP, #Intercom, and #lightning #npmpackages compromised. The attacks, attributed to TeamPCP, involve credential-stealing malware that self-propagates, encrypts stolen data, and exfiltrates it to a new GitHub repository. theregister.com/2026/04/30/sup #tech #media #news

  5. #Supplychainattacks targeting security and developer tools continue, with #SAP, #Intercom, and #lightning #npmpackages compromised. The attacks, attributed to TeamPCP, involve credential-stealing malware that self-propagates, encrypts stolen data, and exfiltrates it to a new GitHub repository. theregister.com/2026/04/30/sup #tech #media #news

  6. #Supplychainattacks targeting security and developer tools continue, with #SAP, #Intercom, and #lightning #npmpackages compromised. The attacks, attributed to TeamPCP, involve credential-stealing malware that self-propagates, encrypts stolen data, and exfiltrates it to a new GitHub repository. theregister.com/2026/04/30/sup #tech #media #news

  7. 🐛 Oh joy, another thrilling episode of "Whack-a-Mole: Software Edition," where 300+ NPM packages show us that open source security is an oxymoron! 🎉 #HelixGuard struts in with their clipboard and magnifying glass, ready to save the day—right after the damage is done. 🔍📝
    helixguard.ai/blog/malicious-s #openSourceSecurity #NPMpackages #softwareVulnerabilities #cybersecurity #HackerNews #ngated

  8. 🐛 Oh joy, another thrilling episode of "Whack-a-Mole: Software Edition," where 300+ NPM packages show us that open source security is an oxymoron! 🎉 #HelixGuard struts in with their clipboard and magnifying glass, ready to save the day—right after the damage is done. 🔍📝
    helixguard.ai/blog/malicious-s #openSourceSecurity #NPMpackages #softwareVulnerabilities #cybersecurity #HackerNews #ngated