Thehackernews
npm Packages Compromise Developer Credentials Across Multiple Platforms
First seen 2 Dec 2025, 18:33 UTC
•
•11.5
Export
Article Content
Browse articles
Malware targeting npm packages has been identified, compromising developer credentials on Windows, Linux, and macOS. The malware bypasses app-level security by targeting system keyrings, leading to the theft of decrypted credentials. Affected users are advised to revoke their credentials and rebuild their environments.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Google Addresses Eighth Chrome Zero-Day Vulnerability in 2025
China-linked Cyber Group Expands Targeting to Southeastern Europe
China-Nexus APT UAT-7290 Targets South Asia Telecoms in Cyber Espionage Campaign
China-linked UAT-7290 Targets Telcos in Cyberespionage Campaign
UAT-7290 Cyber Espionage Targets South Asian Telecoms
New WebKit Zero-Day CVE-2025-14174 Discovered and Exploited