Pnpm — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
10
occurrences
First Seen
January 27, 2026
Last Seen
July 12, 2026

Pnpm is a technology platform tracked across 8 threat clusters and 10 intelligence report mentions on ThreatCluster. First observed January 27, 2026; most recent activity July 12, 2026.

Related Threat Clusters

  • Jscrambler npm Package Compromised in Supply Chain Attack

    On July 11, 2026, multiple malicious versions of the jscrambler npm package were published, exploiting a compromised npm publishing credential. The affected versions (8.14.0, 8.16.0, 8.17.0, 8.18.0, and 8.20.0) included…

    18 articles · Updated July 12, 2026
  • Malicious JetBrains Plugins Exfiltrate AI API Keys from Developers

    A coordinated malware campaign has been uncovered involving at least 15 malicious plugins on the JetBrains Marketplace, designed to steal AI API keys from developers. These plugins, masquerading as AI coding assistants,…

    7 articles · Updated June 16, 2026
  • Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages

    A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…

    697 articles · Updated April 29, 2026
  • Malicious Codex Tool Steals OpenAI Tokens from Developers

    A malicious npm package named 'codexui-android' has been discovered, which masquerades as a legitimate remote UI for OpenAI Codex. This tool, downloaded approximately 27,000 times weekly, has been silently exfiltrating…

    12 articles · Updated May 29, 2026
  • GitHub Breach Linked to Compromised Nx Console Extension

    On May 19, 2026, GitHub announced an investigation into unauthorized access to internal repositories after a malicious Visual Studio Code extension was executed on an employee's device. The attack, attributed to the…

    5 articles · Updated July 7, 2026
  • GitHub Actions Enhances Security Against 'Pwn Request' Attacks

    GitHub has released actions/checkout v7 to mitigate vulnerabilities associated with the pull_request_target workflow trigger, which has been exploited in 'pwn request' attacks. This update, announced on June 18, 2026,…

    9 articles · Updated June 22, 2026
  • Python Developer Avoids Backdoor Attack with AI Code Vetting

    Roman Imankulov, a Python developer, was approached by a fake recruiter from a crypto startup seeking help with faulty proof-of-concept code. Suspicious of the request, he used an AI coding agent to analyze the code,…

    2 articles · Updated June 16, 2026
  • PackageGate Vulnerabilities Affect Major JavaScript Package Managers

    Koi researchers identified a set of vulnerabilities known as 'PackageGate' in NPM, PNPM, VLT, and Bun. These flaws allow attackers to bypass supply chain protections and execute malicious code, posing risks to users of…

    2 articles · Updated January 28, 2026

Recent Intelligence Reports

  • Jscrambler — safedep.io · July 12, 2026
  • Link — edge.prnewswire.com · July 8, 2026
  • Compromised GitHub action codfish/semantic-release-action steals CI/CD secrets — Aikido.Dev · June 24, 2026
  • Python dev saved from disaster by intuition... and AI — Theregister · June 16, 2026
  • Python dev saved from disaster by intuition...and AI — Theregister · June 16, 2026
  • Multiple JetBrains IDE plugins caught stealing AI keys — Aikido.Dev · June 16, 2026
  • Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens — Aikido.Dev · May 27, 2026
  • PackageGate bugs let attackers bypass protections in NPM, PNPM, VLT, and Bun — Securityaffairs · January 28, 2026

CVSS v3.1 Breakdown