<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Home page on Days Since Last NPM Supply Chain Compromise</title><link>https://irateredkite.codeberg.page/time-since-last-node/</link><description>Recent content in Home page on Days Since Last NPM Supply Chain Compromise</description><generator>Hugo</generator><language>en-uk</language><lastBuildDate>Wed, 03 Jun 2026 15:21:54 +0530</lastBuildDate><atom:link href="https://irateredkite.codeberg.page/time-since-last-node/index.xml" rel="self" type="application/rss+xml"/><item><title>IronWorm: Shai-Hulud's rustier cousin</title><link>https://irateredkite.codeberg.page/time-since-last-node/breach-ironworm/</link><pubDate>Wed, 03 Jun 2026 15:21:54 +0530</pubDate><guid>https://irateredkite.codeberg.page/time-since-last-node/breach-ironworm/</guid><description>&lt;p&gt;via &lt;a href="https://research.jfrog.com/post/iron-worm-shai-hulud-rustier-cousin/"&gt;JFrog&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Multiple redhat-cloud-services npm Packages compromised</title><link>https://irateredkite.codeberg.page/time-since-last-node/breach-redhat/</link><pubDate>Mon, 01 Jun 2026 15:21:54 +0530</pubDate><guid>https://irateredkite.codeberg.page/time-since-last-node/breach-redhat/</guid><description>&lt;p&gt;via &lt;a href="https://www.stepsecurity.io/blog/multiple-redhat-cloud-services-npm-packages-compromised"&gt;StepSecurity&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Mini Shai-Hulud Hits @antv Ecosystem, 639 Compromised npm Package Versions</title><link>https://irateredkite.codeberg.page/time-since-last-node/breach-shai-hulud-3/</link><pubDate>Tue, 19 May 2026 15:21:54 +0530</pubDate><guid>https://irateredkite.codeberg.page/time-since-last-node/breach-shai-hulud-3/</guid><description>&lt;p&gt;via &lt;a href="https://socket.dev/blog/antv-packages-compromised"&gt;Socket.Dev&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Postmortem: TanStack npm supply-chain compromise</title><link>https://irateredkite.codeberg.page/time-since-last-node/breach-tanstack/</link><pubDate>Mon, 11 May 2026 15:06:43 +0530</pubDate><guid>https://irateredkite.codeberg.page/time-since-last-node/breach-tanstack/</guid><description>&lt;p&gt;via &lt;a href="https://tanstack.com/blog/npm-supply-chain-compromise-postmortem"&gt;Tanstack&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Official SAP npm packages compromised to steal credentials</title><link>https://irateredkite.codeberg.page/time-since-last-node/breach-sap/</link><pubDate>Wed, 29 Apr 2026 15:06:43 +0530</pubDate><guid>https://irateredkite.codeberg.page/time-since-last-node/breach-sap/</guid><description>&lt;p&gt;via &lt;a href="https://www.bleepingcomputer.com/news/security/official-sap-npm-packages-compromised-to-steal-credentials/"&gt;Bleeping Computer&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Bitwarden CLI npm package compromised to steal developer credentials</title><link>https://irateredkite.codeberg.page/time-since-last-node/breach-bitwarden/</link><pubDate>Thu, 23 Apr 2026 15:21:54 +0530</pubDate><guid>https://irateredkite.codeberg.page/time-since-last-node/breach-bitwarden/</guid><description>&lt;p&gt;via &lt;a href="https://www.bleepingcomputer.com/news/security/bitwarden-cli-npm-package-compromised-to-steal-developer-credentials/"&gt;BleepingComputer&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Namastex.ai npm Packages Hit with TeamPCP-Style CanisterWorm Malware</title><link>https://irateredkite.codeberg.page/time-since-last-node/breach-namastex/</link><pubDate>Wed, 22 Apr 2026 15:21:54 +0530</pubDate><guid>https://irateredkite.codeberg.page/time-since-last-node/breach-namastex/</guid><description>&lt;p&gt;via &lt;a href="https://socket.dev/blog/namastex-npm-packages-compromised-canisterworm"&gt;Socket.dev&lt;/a&gt;&lt;/p&gt;</description></item><item><title>OtterCookie Expands Targeting to AI Coding Tools: Analysis of a Trojanized npm Campaign</title><link>https://irateredkite.codeberg.page/time-since-last-node/breach-ottercookie/</link><pubDate>Sat, 04 Apr 2026 15:21:54 +0530</pubDate><guid>https://irateredkite.codeberg.page/time-since-last-node/breach-ottercookie/</guid><description>&lt;p&gt;via &lt;a href="https://cyberandramen.net/2026/04/04/ottercookie-expands-targeting-to-ai-coding-tools-analysis-of-a-trojanized-npm-campaign/"&gt;Cyber &amp;amp; Ramen&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Thirty-Six Malicious npm Strapi Packages Deploy Redis RCE, Database Theft, and Persistent C2</title><link>https://irateredkite.codeberg.page/time-since-last-node/breach-redis/</link><pubDate>Fri, 03 Apr 2026 15:21:54 +0530</pubDate><guid>https://irateredkite.codeberg.page/time-since-last-node/breach-redis/</guid><description>&lt;p&gt;via &lt;a href="https://safedep.io/malicious-npm-strapi-plugin-events-c2-agent/"&gt;SafeDep&lt;/a&gt;&lt;/p&gt;</description></item><item><title>axios Compromised on npm - Malicious Versions Drop Remote Access Trojan</title><link>https://irateredkite.codeberg.page/time-since-last-node/breach-axios/</link><pubDate>Mon, 30 Mar 2026 15:21:54 +0530</pubDate><guid>https://irateredkite.codeberg.page/time-since-last-node/breach-axios/</guid><description>&lt;p&gt;via &lt;a href="https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan"&gt;The Step Security&lt;/a&gt;&lt;/p&gt;</description></item><item><title>TeamPCP deploys CanisterWorm on NPM following Trivy compromise</title><link>https://irateredkite.codeberg.page/time-since-last-node/breach-canisterworm/</link><pubDate>Fri, 20 Mar 2026 15:21:54 +0530</pubDate><guid>https://irateredkite.codeberg.page/time-since-last-node/breach-canisterworm/</guid><description>&lt;p&gt;via &lt;a href="https://www.aikido.dev/blog/teampcp-deploys-worm-npm-trivy-compromise"&gt;Akido&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Cline CLI npm Package Compromised via Suspected Cache Poisoning Attack</title><link>https://irateredkite.codeberg.page/time-since-last-node/breach-openclaw/</link><pubDate>Wed, 18 Feb 2026 15:21:54 +0530</pubDate><guid>https://irateredkite.codeberg.page/time-since-last-node/breach-openclaw/</guid><description>&lt;p&gt;via &lt;a href="https://socket.dev/blog/cline-cli-npm-package-compromised-via-suspected-cache-poisoning-attack"&gt;Socket.Dev&lt;/a&gt;&lt;/p&gt;</description></item><item><title>NPM Package With 56K Downloads Caught Stealing WhatsApp Messages</title><link>https://irateredkite.codeberg.page/time-since-last-node/breach-lotusbail/</link><pubDate>Sun, 21 Dec 2025 15:21:54 +0530</pubDate><guid>https://irateredkite.codeberg.page/time-since-last-node/breach-lotusbail/</guid><description>&lt;p&gt;via &lt;a href="https://www.koi.ai/blog/npm-package-with-56k-downloads-malware-stealing-whatsapp-messages"&gt;Koi Security&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Two Years, 17K Downloads: The NPM Malware That Tried to Gaslight Security Scanners</title><link>https://irateredkite.codeberg.page/time-since-last-node/breach-eslint-typosquat/</link><pubDate>Sun, 30 Nov 2025 15:21:54 +0530</pubDate><guid>https://irateredkite.codeberg.page/time-since-last-node/breach-eslint-typosquat/</guid><description>&lt;p&gt;via &lt;a href="https://www.koi.ai/blog/two-years-17k-downloads-the-npm-malware-that-tried-to-gaslight-security-scanners"&gt;Koi AI&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Shai-Hulud 2.0 Supply Chain Attack: 25K+ npm Repos Exposed</title><link>https://irateredkite.codeberg.page/time-since-last-node/breach-shai-hulud-2/</link><pubDate>Mon, 24 Nov 2025 15:21:54 +0530</pubDate><guid>https://irateredkite.codeberg.page/time-since-last-node/breach-shai-hulud-2/</guid><description>&lt;p&gt;via &lt;a href="https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack"&gt;Wiz.Io&lt;/a&gt;&lt;/p&gt;</description></item><item><title>npm Malware Campaign Uses Adspect Cloaking to Deliver Malicious Redirects</title><link>https://irateredkite.codeberg.page/time-since-last-node/breach-adspect/</link><pubDate>Mon, 17 Nov 2025 15:21:54 +0530</pubDate><guid>https://irateredkite.codeberg.page/time-since-last-node/breach-adspect/</guid><description>&lt;p&gt;via &lt;a href="https://socket.dev/blog/npm-malware-campaign-uses-adspect-cloaking-to-deliver-malicious-redirects"&gt;Socket.dev&lt;/a&gt;&lt;/p&gt;</description></item><item><title>IndonesianFoods worm publishes more than 86,000 malicious NPM packages</title><link>https://irateredkite.codeberg.page/time-since-last-node/breach-indonesian-foods/</link><pubDate>Thu, 13 Nov 2025 15:21:54 +0530</pubDate><guid>https://irateredkite.codeberg.page/time-since-last-node/breach-indonesian-foods/</guid><description>&lt;p&gt;via &lt;a href="https://sourcecodered.com/indonesianfoods-npm-worm/"&gt;SourceCodeRED&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Malicious NPM Package Found Targeting GitHub By Typosquatting on GitHub Action Packages</title><link>https://irateredkite.codeberg.page/time-since-last-node/breach-gh-actions/</link><pubDate>Mon, 10 Nov 2025 15:21:54 +0530</pubDate><guid>https://irateredkite.codeberg.page/time-since-last-node/breach-gh-actions/</guid><description>&lt;p&gt;via &lt;a href="https://www.veracode.com/blog/malicious-npm-package-targeting-github-actions/"&gt;Veracode&lt;/a&gt;&lt;/p&gt;</description></item><item><title>MUT-4831: Trojanized npm packages deliver Vidar infostealer malware</title><link>https://irateredkite.codeberg.page/time-since-last-node/breach-vidar/</link><pubDate>Thu, 06 Nov 2025 15:21:54 +0530</pubDate><guid>https://irateredkite.codeberg.page/time-since-last-node/breach-vidar/</guid><description>&lt;p&gt;via &lt;a href="https://securitylabs.datadoghq.com/articles/mut-4831-trojanized-npm-packages-vidar/"&gt;Datadog&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Invisible npm malware pulls a disappearing act – then nicks your tokens</title><link>https://irateredkite.codeberg.page/time-since-last-node/breach-phantomraven/</link><pubDate>Thu, 30 Oct 2025 15:21:54 +0530</pubDate><guid>https://irateredkite.codeberg.page/time-since-last-node/breach-phantomraven/</guid><description>&lt;p&gt;via &lt;a href="https://www.theregister.com/2025/10/30/phantomraven_npm_malware/"&gt;The Register&lt;/a&gt;&lt;/p&gt;</description></item><item><title>10 npm Typosquatted Packages Deploy Multi-Stage Credential Harvester</title><link>https://irateredkite.codeberg.page/time-since-last-node/breach-typosquat/</link><pubDate>Tue, 28 Oct 2025 15:21:54 +0530</pubDate><guid>https://irateredkite.codeberg.page/time-since-last-node/breach-typosquat/</guid><description>&lt;p&gt;via &lt;a href="https://socket.dev/blog/10-npm-typosquatted-packages-deploy-credential-harvester"&gt;socket.dev&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Post-exploitation framework now also delivered via npm</title><link>https://irateredkite.codeberg.page/time-since-last-node/breach-adaptixc2/</link><pubDate>Fri, 17 Oct 2025 15:21:54 +0530</pubDate><guid>https://irateredkite.codeberg.page/time-since-last-node/breach-adaptixc2/</guid><description>&lt;p&gt;via &lt;a href="https://securelist.com/adaptixc2-agent-found-in-an-npm-package/117784/"&gt;Kaspersky&lt;/a&gt;&lt;/p&gt;</description></item><item><title>175 npm packages, unpkg CDN abused for phishing infrastructure</title><link>https://irateredkite.codeberg.page/time-since-last-node/breach-unpkg/</link><pubDate>Mon, 13 Oct 2025 00:00:00 +0000</pubDate><guid>https://irateredkite.codeberg.page/time-since-last-node/breach-unpkg/</guid><description>&lt;p&gt;via &lt;a href="https://www.scworld.com/news/175-npm-packages-unpkg-cdn-abused-for-phishing-infrastructure"&gt;SC Media&lt;/a&gt;&lt;/p&gt;</description></item><item><title>First Malicious MCP in the Wild: The Postmark Backdoor That's Stealing Your Emails</title><link>https://irateredkite.codeberg.page/time-since-last-node/breach-postmark-mcp/</link><pubDate>Thu, 25 Sep 2025 15:21:54 +0530</pubDate><guid>https://irateredkite.codeberg.page/time-since-last-node/breach-postmark-mcp/</guid><description>&lt;p&gt;via &lt;a href="https://www.koi.security/blog/postmark-mcp-npm-malicious-backdoor-email-theft"&gt;koi.security&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Shai-Hulud Worm Compromises npm Ecosystem in Supply Chain Attack</title><link>https://irateredkite.codeberg.page/time-since-last-node/breach-shai-hulud/</link><pubDate>Tue, 23 Sep 2025 15:21:54 +0530</pubDate><guid>https://irateredkite.codeberg.page/time-since-last-node/breach-shai-hulud/</guid><description>&lt;p&gt;via &lt;a href="https://unit42.paloaltonetworks.com/npm-supply-chain-attack/"&gt;Palo Alto&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Hackers hijack npm packages with 2 billion weekly downloads in supply chain attack</title><link>https://irateredkite.codeberg.page/time-since-last-node/breach-qix/</link><pubDate>Mon, 08 Sep 2025 15:21:54 +0530</pubDate><guid>https://irateredkite.codeberg.page/time-since-last-node/breach-qix/</guid><description>&lt;p&gt;via &lt;a href="https://www.bleepingcomputer.com/news/security/hackers-hijack-npm-packages-with-2-billion-weekly-downloads-in-supply-chain-attack/"&gt;Bleeping Computer&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Hijacked S3 buckets used in attacks on npm packages</title><link>https://irateredkite.codeberg.page/time-since-last-node/breach-bignum/</link><pubDate>Mon, 19 Jun 2023 15:21:54 +0530</pubDate><guid>https://irateredkite.codeberg.page/time-since-last-node/breach-bignum/</guid><description>&lt;p&gt;via &lt;a href="https://www.theregister.com/2023/06/19/npm_s3_buckets_malware/"&gt;The Register&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Protestware on the rise: Why developers are sabotaging their own code</title><link>https://irateredkite.codeberg.page/time-since-last-node/breach-protestware/</link><pubDate>Wed, 27 Jul 2022 15:21:54 +0530</pubDate><guid>https://irateredkite.codeberg.page/time-since-last-node/breach-protestware/</guid><description>&lt;p&gt;via &lt;a href="https://techcrunch.com/2022/07/27/protestware-code-sabotage/"&gt;TechCrunch&lt;/a&gt;&lt;/p&gt;</description></item><item><title>BIG sabotage: Famous npm package deletes files to protest Ukraine war</title><link>https://irateredkite.codeberg.page/time-since-last-node/breach-peacenotwar/</link><pubDate>Thu, 17 Mar 2022 15:21:54 +0530</pubDate><guid>https://irateredkite.codeberg.page/time-since-last-node/breach-peacenotwar/</guid><description>&lt;p&gt;via &lt;a href="https://www.bleepingcomputer.com/news/security/big-sabotage-famous-npm-package-deletes-files-to-protest-ukraine-war/"&gt;The Register&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Dev corrupts NPM libs colors and faker breaking thousands of apps</title><link>https://irateredkite.codeberg.page/time-since-last-node/breach-faker/</link><pubDate>Sun, 09 Jan 2022 15:21:54 +0530</pubDate><guid>https://irateredkite.codeberg.page/time-since-last-node/breach-faker/</guid><description>&lt;p&gt;via &lt;a href="https://www.bleepingcomputer.com/news/security/dev-corrupts-npm-libs-colors-and-faker-breaking-thousands-of-apps/"&gt;Bleeping Computer&lt;/a&gt;&lt;/p&gt;</description></item><item><title>NPM package with 3 million weekly downloads had a severe vulnerability</title><link>https://irateredkite.codeberg.page/time-since-last-node/breach-pac-resolver/</link><pubDate>Thu, 02 Sep 2021 15:21:54 +0530</pubDate><guid>https://irateredkite.codeberg.page/time-since-last-node/breach-pac-resolver/</guid><description>&lt;p&gt;via &lt;a href="https://arstechnica.com/information-technology/2021/09/npm-package-with-3-million-weekly-downloads-had-a-severe-vulnerability/"&gt;Ars Technica&lt;/a&gt;&lt;/p&gt;</description></item><item><title>How 17 Lines of Code Took Down Silicon Valley's Hottest Startups</title><link>https://irateredkite.codeberg.page/time-since-last-node/breach-leftpad/</link><pubDate>Sun, 24 Mar 2019 15:21:54 +0530</pubDate><guid>https://irateredkite.codeberg.page/time-since-last-node/breach-leftpad/</guid><description>&lt;p&gt;via &lt;a href="https://www.huffpost.com/entry/how-17-lines-of-code-took_b_9532846"&gt;Huffington Post&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Check your repos... Crypto-coin-stealing code sneaks into fairly popular NPM lib (2m downloads per week)</title><link>https://irateredkite.codeberg.page/time-since-last-node/breach-flatmap-stream/</link><pubDate>Mon, 26 Nov 2018 15:21:54 +0530</pubDate><guid>https://irateredkite.codeberg.page/time-since-last-node/breach-flatmap-stream/</guid><description>&lt;p&gt;via &lt;a href="https://www.theregister.com/2018/11/26/npm_repo_bitcoin_stealer/"&gt;Ars Technica&lt;/a&gt;&lt;/p&gt;</description></item></channel></rss>