Npm - Tool

Threat entity extracted from intelligence sources

Frequency
388
occurrences
First Seen
October 29, 2025
Last Seen
August 31, 2026

Related Threat Clusters

Recent Intelligence Reports

  • Communication Channel Identity Risks — unit42.paloaltonetworks.com · August 31, 2026
  • Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more — Grahamcluley · August 28, 2026
  • Australian cops cuff alleged TeamPCP masterminds — Theregister · August 28, 2026
  • Hackers Turn Trusted npm Mirrors Into Hosts for Fake Cloudflare ClickFix Pages. — Gbhackers · August 26, 2026
  • Crooks push Mac malware through fake OpenAI Codex ads — Theregister · August 25, 2026
  • [SecurityIntel] 22 Aug | GitLab CVE-2026-19478 Under Active Exploitation — Buttondown · August 22, 2026
  • CVE-2026-57998: better-npm-audit OS Command Injection via registry flag [HIGH] CVSS 8.5 Exploit Intelligence - Recent CVEs / 3h better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm audit command by interpolating the user-supplied --registry option into a command string in src/handlers/handleInput.ts without validation or quoting, then passes that string to child_process.exec() in index.ts, which spawns a shell. A registry value containing shell metacharacters such as a — exploit-intel.com · August 22, 2026
  • North Korean Hackers Tied to Rust Supply Chain Attack — Infosecurity-Magazine · August 21, 2026

CVSS v3.1 Breakdown