NodeJS is a technology platform tracked across 7 threat clusters and 7 intelligence report mentions on ThreatCluster. First observed January 27, 2026; most recent activity July 14, 2026.
CVE-2026-48527 is a stored cross-site scripting (XSS) vulnerability in HAX CMS, affecting versions up to 26.0.0. The vulnerability exists in the `/system/api/saveNode` endpoint, where authenticated users with page…
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
Bitdefender researchers have uncovered a malicious extension for the Windsurf IDE that deploys a multi-stage NodeJS stealer via the Solana blockchain. Disguised as a legitimate R language support tool for Visual Studio…
Recent vulnerabilities in Node.js have been identified, including a critical symlink traversal issue and a command injection vulnerability. The CVSS scores for these vulnerabilities are 9.5 and 8.0 respectively,…
Recent analysis reveals that Rhysida and Interlock ransomware groups are interconnected through a shared ecosystem of malware tools, including the Supper backdoor. Both groups utilize initial access brokers and a…
In a recent ransomware attack, the Hive0163 group utilized a new malware strain named Slopoly, suspected to be generated by AI tools. The attack began with a ClickFix social engineering tactic, allowing the threat…
A critical vulnerability in the vm2 sandboxing library for Node.js has been identified, enabling attackers to escape the sandbox and execute arbitrary code on affected systems. This flaw poses a significant risk to…