ThreatCluster
  • Feed
  • Saved
THREAT HUNTING
  • Domains
  • IP Addresses
  • File Hashes
  • CVEs
THREAT INTELLIGENCE
  • APT Groups
  • Ransomware Groups
  • Malware Families
  • Attack Types
  • MITRE ATT&CK
  • Security Standards
  • Vulnerability Types
BUSINESS INTELLIGENCE
  • Companies
  • Industry Sectors
  • Security Vendors
  • Government Agencies
  • Countries
  • Platforms
Home / Feed / Article

NPM package ‘is’ with 2.8M weekly downloads infected devs with malware

Threat Score:
52
BleepingComputer
3 days ago
Part of cluster #1351
NPM package ‘is’ with 2.8M weekly downloads infected devs with malware

Overview

NPM package ‘is’ with 2.8M weekly downloads infected devs with malware Bill Toulas July 23, 2025 11:57 AM 0 The popular NPM package 'is' has been compromised in a supply chain attack that injected backdoor malware, giving attackers full access to compromised devices. This occurred after maintainer accounts were hijacked via phishing, followed by unauthorized owner changes that went unnoticed for several hours, potentially compromising many developers who downloaded the new releases. The 'is' pac...

Continue Reading on Original Site

Related Articles

5 articles
1
Allianz Life confirms data breach impacts majority of 1.4 million customers

Allianz Life confirms data breach impacts majority of 1.4 million customers

BleepingComputer • 5 hours ago

Allianz Life confirms data breach impacts majority of 1.4 million customers Lawrence Abrams July 26, 2025 02:00 PM 0 Insurance company Allianz Life has confirmed that the personal information for the "majority" of its 1.4 million customers was exposed in a data breach that occurred earlier this month. "On July 16, 2025, a malicious threat actor gained access to a third-party, cloud-based CRM system used by Allianz Life Insurance Company of North America (Allianz Life)," an Allianz Life spokesper

Score
77
Read more
2

Allianz Life says ‘majority’ of customers’ personal data stolen in cyberattack

TechCrunch • 9 hours ago

Exclusive: Allianz Life said the "majority" of its customers and employees had data stolen in the July cyberattack. The insurance giant has more than 125 million customers worldwide.

Score
69
Read more
3

Hackers Compromised Official Gaming Mouse Software to Deliver Windows-based Xred Malware

Cybersecurity News • 13 hours ago

Gaming peripheral manufacturer Endgame Gear has confirmed that hackers successfully compromised its official software distribution system, using the company’s OP1w 4K V2 mouse configuration tool to spread dangerous Xred malware to unsuspecting customers for nearly two weeks. The security breach, which occurred between June 26 and July 9, 2025, represents a troubling example of supply […]

Score
69
Read more
4

From Friction to Function: Optimising Onboarding in an Age of AML, AI and Rising Risk

Finextra Security • 8 hours ago

From Friction to Function: Optimising Onboarding in an Age of AML, AI and Rising Risk Join this webinar, hosted in association with nCino, to the challenges of commercial onboarding, particularly in the context of increasing regulations like the EU AML Directive and an emphasis on the importance of data strategy, AI, and streamlining Client Lifecycle Management (CLM). How can banks scale AML compliance in an increasingly complex and high-risk environment without compromising the commercial clien

Score
68
Read more
5

Microsoft Patches ‘ToolShell’ Zero-Days Exploited to Hack SharePoint Servers

SecurityWeek • 5 days ago

Microsoft has started releasing updates to fix the exploited SharePoint zero-days tracked as CVE-2025-53770 and CVE-2025-53771.

Score
68
Read more

Save to Folder

Choose a folder to save this article:

Article Intelligence

Key entities and indicators for this article

INDUSTRIES
Communications
ATTACK TYPES
Command and Control
Phishing
Remote Code Execution
Supply Chain Attack
VULNERABILITIES
Remote Code Execution
PLATFORMS
Windows
MITRE ATT&CK
Phishing
RANSOMWARE
DN
Korean
Snatch
core
MALWARE
Snatch
ARTICLE INFORMATION
Article #4447
Published 3 days ago
BleepingComputer