Skip to content
Vela
Tech FrontlineBiotech & HealthPolicy & LawGrowth & LifeSpotlight
Set Interest Preferences中文

#NPM

7 articles
Cybersecurity conceptual art: digital lock broken, binary codes, green glowing data streams, dark mo
Tech Frontline

Security Alert: Malicious npm Packages and VPN Vulnerabilities Exposed

A massive security breach occurred in the npm ecosystem as attackers bypassed trust signals to distribute malicious code, while law enforcement successfully compromised a VPN used for criminal anonymity.

JasonJason··2 min read
A conceptual digital visualization of a software supply chain breakdown, red corrupted nodes in a bl
Tech Frontline

The Software Supply Chain Crisis: How TeamPCP Exploits Open Source

The hacking group TeamPCP has compromised npm repositories by stealing maintainer credentials, effectively bypassing provenance verification. This highlights critical vulnerabilities in the human-centric security model of open-source supply chains.

KenjiKenji··2 min read
A cybersecurity-themed visual showing a complex chain of glowing digital code blocks, with several b
Tech Frontline

Supply Chain Attack Targets NPM Ecosystem: Hundreds of Malicious Packages Bypass Provenance

A hacker group, TeamPCP, stole maintainer accounts to publish over 600 malicious npm packages that bypassed Sigstore verification. This highlights major logic vulnerabilities in digital signatures and open-source supply chain risks.

KenjiKenji··2 min read
A digital visual representation of a software supply chain conveyor belt, with one link being cracke
Tech Frontline

Axios NPM Supply Chain Attack: A Security Wake-Up Call for 80% of Cloud Environments

Attackers compromised the maintainer's token for the popular Axios library to distribute a remote access trojan. Given its integration in 80% of cloud environments, the breach poses a significant supply chain threat.

KenjiKenji··1 min read
A digital illustration of a supply chain represented by interlocking digital gears being infected by
Tech Frontline

Supply Chain Security Crisis: Vulnerabilities Plague NPM Packages

The popular axios npm library was compromised by hackers who injected a cross-platform trojan, affecting millions of cloud and code environments. Experts warn enterprises to urgently audit their dependencies and tighten supply chain security.

KenjiKenji··1 min read
A digital visual of an insecure software supply chain, a broken link in a chain made of code blocks,
Tech Frontline

The Axios Breach: Exposing the Fragile Links in the npm Supply Chain

The popular open-source library axios was compromised via a stolen maintenance token, planting a RAT. The incident underscores the systemic risks in software supply chains, urging organizations to strengthen identity and dependency management.

KenjiKenji··2 min read
Abstract digital illustration of a supply chain network breaking, with lines of code fragments falli
Tech Frontline

The Axios NPM Supply Chain Attack: Exposing Fragility in Web Infrastructure

The widely-used Axios library was compromised when an attacker stole a maintainer's npm token, pushing malicious versions containing a remote access trojan. The incident underscores the severe risks inherent in modern software supply chain trust.

KenjiKenji··2 min read