Latest News

Breaking

Post Top Ad

Your Ad Spot

Monday, February 23, 2026

Malicious npm Packages Harvest Crypto Keys, CI Secrets, and API Tokens

Cybersecurity researchers have disclosed what they say is an active "Shai-Hulud-like" supply chain worm campaign that has leveraged a cluster of at least 19 malicious npm packages to enable credential harvesting and cryptocurrency key theft. The campaign has been codenamed SANDWORM_MODE by supply chain security company Socket. As with prior Shai-Hulud attack waves, the malicious code embedded

source https://thehackernews.com/2026/02/malicious-npm-packages-harvest-crypto.html

No comments:

Post a Comment

please do not enter any spam link in the comment box

Post Top Ad

Your Ad Spot

Pages