Seven Malicious npm Packages Use Blockchain-Based C2 for RAT Distribution17. July 2026CybersecuritySeven malicious npm packages in the Vite supply chain use a four-tier blockchain C2 infrastructure (Tron) to distribute a remote access trojan. Share on:
Fake Payment SDKs on npm and PyPI Steal Developer Data and Access Keys14. July 2026CybersecurityAt least 17 fake payment SDKs on npm and PyPI steal development-related access credentials such as API keys and AWS login data through disguised packages that imitate legitimate application programming interfaces. Share on:
148 npm Packages Disguised as Student Proxies – Browsers Turned into DDoS Bots14. July 2026Cybersecurity148 npm packages were abused as student proxies to turn browser visitors into DDoS attack bots, without developers being the primary targets. Share on: