The packages @joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4 contain a JavaScript implant that decrypts and executes malicious code on import.
Malware in jscrambler 8.14.0 is activated via the preinstall hook without explicit import or CLI command—installation alone is sufficient for execution.
The malware in jscrambler 8.14.0 is activated by the preinstall hook without explicit import or CLI command — installation alone is sufficient for execution.
The malware in jscrambler 8.14.0 is activated by the preinstall hook without explicit import or CLI command—installation alone is sufficient for execution.
A supply-chain attack on Red Hat npm packages exploits install-time execution and credential harvesting to infiltrate developer and CI/CD systems with self-propagating malware.
An npm package disguised as an OpenAI Codex interface with 29,000 weekly downloads steals authentication tokens and enables attackers to abuse APIs under stolen identities.