
Security
Malicious NuGet and npm Packages Target Developers with Data Theft and Backdoors
2/25/2026

Security
Malicious npm Packages Harvest Crypto Keys, CI Secrets, and API Tokens
2/23/2026

Vulnerabilities
Cline CLI Supply Chain Attack Exploits AI Agent to Distribute OpenClaw
2/21/2026

Vulnerabilities
Cline CLI Compromise Triggers Unauthorized OpenClaw Installations
2/20/2026

Dev
npmx Emerges as a Modern Package Explorer for npm Registry
2/14/2026

Security
npm's Authentication Overhaul: Progress Made, Risks Remain
2/13/2026

Security
Lazarus Group Infects npm and PyPI Ecosystems with Malicious Packages via Fake Job Campaign
2/13/2026

Security
Compromised dYdX npm and PyPI Packages Deliver Wallet Stealers and RAT Malware
2/6/2026

Vulnerabilities
Hackers Exploit Metro4Shell RCE Flaw in React Native CLI npm Package
2/3/2026

Security
n8n Supply Chain Attack Abuses Community Nodes to Steal OAuth Tokens
1/12/2026
Frontend
npm's Tradeoffs: How Growth-First Design Fueled JavaScript's Rise and Created Docker Dependency
12/27/2025

Security
Shai-Hulud Attack Exposes npm's Supply Chain Crisis: How to Defend Against Self-Replicating Worms
9/19/2025

AI
Worm-Style 'Shai-Hulud' Attack Infects 187 npm Packages in Self-Propagating Supply Chain Assault
9/16/2025