Malicious code hidden in joyfill packages executes upon loading the CommonJS entry point—not via lifecycle hooks—and uses a multi-stage blockchain infrastructure for payload delivery that security researchers attribute to a presumed North Korean operation.
Nearly 7,600 malicious GitHub repositories lure developers and AI systems with fake AI integration tools and MCP servers to install SmartLoader malware.
The popular HTTP header extension ModHeader contained code to capture browser history that could have been activated through a simple update without additional permissions.
At least 17 fake payment SDKs on npm and PyPI steal development-related access credentials such as API keys and AWS login data through disguised packages that imitate legitimate application programming interfaces.
AI agents with self-execution privileges become an attack vector in the software supply chain when they install tampered packages without human approval.
Eight manipulated Pyrogram packages on PyPI allow attackers to execute Python code and shell commands on production Telegram bot servers and exfiltrate credentials and database connections.
ChocoPoC is distributed through manipulated Python packages in seemingly legitimate GitHub exploits, gaining access to infected systems across multiple dependency levels.