Npm Registry is a technology platform tracked across 11 threat clusters and 12 intelligence report mentions on ThreatCluster. First observed October 30, 2025; most recent activity May 28, 2026.
ESET's latest APT Activity Report reveals that from October 2025 to March 2026, China-aligned threat actors engaged in extensive espionage campaigns, particularly in Venezuela and the Gulf region. Following U.S.…
A coordinated supply chain attack has been discovered involving 36 malicious npm packages that impersonate Strapi CMS plugins. These packages were published to the npm registry and are designed to exploit Redis for…
GitLab has patched a critical two-factor authentication bypass vulnerability, tracked as CVE-2026-0723, affecting both Community and Enterprise editions of its application development platform. The flaw allows attackers…
GoPlus has issued a warning regarding 26 malware packages released by North Korean hackers on the npm registry. These packages include an installation script that executes malicious code, which downloads and runs a…
APT group Evasive Panda is using DNS poisoning to deliver MgBot malware, targeting U.S. and allied manufacturing and healthcare organizations. Additionally, a spearphishing campaign is exploiting the npm registry to…
Three malicious npm packages, bitcoin-main-lib, bitcoin-lib-js, and bip40, have been uploaded to the public npm registry, targeting JavaScript developers to steal sensitive data such as browser logins, API keys, and…
A malware campaign named PhantomRaven has been active since August 2025, compromising 126 npm packages and stealing developer credentials, including npm tokens and GitHub credentials. Researchers at Koi Security…
Trust Wallet reported that approximately $8.5 million in cryptocurrency was stolen from over 2,500 users due to a cyberattack linked to the Shai-Hulud npm supply chain attack. The attackers accessed Trust Wallet’s…
A coordinated token farming campaign has resulted in over 150,000 malicious packages flooding the npm registry, targeting the tea.xyz protocol. Discovered by Amazon Inspector researchers, this incident is described as…
Researchers at Koi Security discovered a malware campaign named PhantomRaven that has been active since August 2025, compromising 126 npm packages. The malicious packages have been downloaded over 86,000 times and are…