Feeds.Feedburner
Malicious NPM Packages Downloaded Over 86,000 Times by Users
First seen 13 Nov 2025, 17:30 UTC
•
•24.3
Export
Article Content
Browse articles
A spam campaign involving tens of thousands of malicious NPM packages has been identified, likely orchestrated by an Indonesian threat actor. These packages, which have random names, can fetch dependencies from untrusted sites, posing risks to users who download them.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Active Exploitation of GitLab CVE-2026-19478 and Microsoft Entra ID Flaw
Sandworm Launches Wiper Malware Campaign Against Ukrainian Organizations
Malware Spread via Fake Polymarket Trading Bot Targets DeFi Developers
ShinyHunters Exploits Oracle PeopleSoft Zero-Day Vulnerability
North Korean Hackers Target Open Source Software Supply Chain via npm Packages
NPM Packages Distribute PylangGhost RAT in Supply Chain Attack