npm granular access tokens configured to bypass 2FA can no longer create tokens, change maintainers, or manage org membership as of July 31, 2026 — closing the attack chain TeamPCP exploited across ...
GitHub's supply chain defense map catalogs nine shipped controls across npm and GitHub Actions — covering pwn-request ...
The cloud computing giant said in a blog post on July 29 that compromises of the axios, debug, chalk and typo-crypto libraries were carried out by the same group, known as Saphire Sleet, BlueNoroff ...
AWS Links Npm Attacks To North Korean Hackers Arabian Post. clearfix>Amazon Web Services has attributed a series of compromises involving widely used npm software packages, including Axios, Debug and ...
A DPRK-linked threat actor has been tied to four separate compromises of widely used JavaScript libraries since March 2025, ...
Amazon threat researchers found one threat actor behind four distinct open source compromises, including the March 2026 ...
Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ...
Researchers say Sapphire Sleet socially engineered maintainers before publishing malicious updates through trusted accounts ...
GitHub Actions will hold potentially malicious workflows until a collaborator with write access approves them.
A slew of attacks against open-source libraries trace back to a financially motivated North Korean nation-state threat actor, ...
The malicious dependency used an npm “postinstall” command, which automatically runs code when a package is installed. Its obfuscated downloader identified the victim’s operating system and deployed a ...