www.reversinglabs.com Rise of Malicious npm Packages Threatens Developer Trust
Article Content
- •1.8 million malicious packages logged, with npm comprising 96.6% of the total.
- •ReversingLabs identified a malicious npm package targeting Twilio developers to exfiltrate data.
- •npm plans to implement pre-publish scanning to combat the rising threat of malicious packages.
As of Q2 2026, Sonatype Research logged 1.8 million malicious packages, with npm accounting for 96.6% of this total. The quarter saw a surge in repository abuse, trojan-class malware, and maintainer compromises, indicating a shift towards targeting trusted developer workflows. ReversingLabs reported a specific malicious npm campaign that compromised packages related to Twilio, aiming to exfiltrate sensitive data. The number of malicious npm packages has risen sharply, with 5723 unique packages identified by August 2026, surpassing the total for all of 2024. Despite npm's efforts to implement pre-publish scanning to mitigate these threats, the volume of malicious packages continues to grow. Attackers are employing social engineering tactics and exploiting trusted packages, with notable campaigns like Shai-Hulud leading to widespread infections. The overall threat landscape remains concerning, with a significant concentration of malicious activity across various ecosystems, particularly npm, PyPI, and NuGet.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Shai-hulud and Twilio in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
North Korean Hackers Deploy Mac Backdoors via Fake Job Tests Targeting IT Firms North Korean threat actor Jade Sleet, also known as TraderTraitor, has been linked to a breach of an Indian IT services provider using macOS backdoors named FLATROOF and ROOFDECK. The attack involved social engineering tactics, where fake job interview assignments were used to lure DevOps engineers into executing…
UAC-0099 Uses GuardBreaker to Evade AI Malware Detection Russian-linked hackers from the group UAC-0099 have developed a new technique called GuardBreaker to evade AI-assisted malware analysis. This method involves embedding a nuclear weapon prompt in malicious VBS scripts, which distracts AI systems from analyzing the actual malware code. The script is designed to download…